Close Menu
    What's Hot

    Opinion | Tucker Carlson’s Big Bet

    California Election Live Updates: Primary Battles Could Set Direction for California and Congress

    Protests Grow in Albania Over Kushner-Linked Project

    Facebook X (Twitter) Instagram
    Trending
    • Opinion | Tucker Carlson’s Big Bet
    • California Election Live Updates: Primary Battles Could Set Direction for California and Congress
    • Protests Grow in Albania Over Kushner-Linked Project
    • How She Turned Her Beachside Cart Into a $332 Million Franchise
    • World Cup final squads ranked: Of all 48 national teams, who can win this summer?
    • Ibrahima Konate transfer news: Defender edges closer to joining Real Madrid as talks continue with LaLiga giants | Football News
    • How these surprisingly likable Knicks have mastered the art of the buddy comedy
    • Partiful Is Putting Ticket Payments on Its Platform
    interluknewsinterluknews
    • Home
    • Business
      • Corporate News
      • Industry Insights
      • Startups & Entrepreneurship
      • Technology & Innovation
    • Economy
      • Economic Policy
      • Financial Analysis
      • Inflation & Interest Rates
      • Trade & Markets
    • Global
      • Conflicts & Security
      • Diplomacy
      • Global Trends
      • International Affairs
    • Lifestyle
      • Fashion
      • Food & Dining
      • Personal Development
      • Travel
    • Opinion
      • Columns
      • Editorials
      • Expert Opinions
      • Reader Voices
    • More
      • Politics
        • Elections
        • Government & Policy
        • International Relations
        • Political Analysis
      • Sports
        • Cricket
        • Football / Soccer
        • International Sports
        • Local Sports
      • Technology
        • Artificial Intelligence
        • Cybersecurity
        • Gadgets & Reviews
        • Tech News
      • South Africa News
    Facebook X (Twitter) Instagram
    interluknewsinterluknews
    Cybersecurity

    Gamaredon Exploits WinRAR to Deliver GammaWorm and GammaSteel Against Ukraine

    adminBy adminJune 2, 2026No Comments3 Mins Read
    Share Facebook Twitter Pinterest Copy Link Telegram LinkedIn Tumblr Email
    Gamaredon Exploits WinRAR to Deliver GammaWorm and GammaSteel Against Ukraine
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananJun 02, 2026Threat Intelligence / Malware

    Gamaredon Exploits WinRAR to Deliver GammaWorm and GammaSteel Against Ukraine

    The Russian hacking group known as Gamaredon has been attributed to the continued exploitation of a WinRAR vulnerability to deliver multiple malware families aimed at data theft and propagation.

    Per Sekoia, the activity involves the weaponization of CVE-2025-8088, a path traversal flaw in WinRAR, to launch an HTML Application payload dubbed GammaPhish, which is then used to retrieve an intermediate Visual Basic Script (VBScript) downloaders codenamed GammaLoad. The infection chain was observed by the French cybersecurity company in January 2026.

    “Their primary objectives are to fingerprint the host system, update the network configuration in the registry using dead drop resolvers (DDRs), fetch and execute arbitrary VBScript payloads from the C2 servers,” Sekoia said.

    One of the payloads is a VBScript worm known as GammaWorm that establishes persistence via scheduled tasks and is designed to hide legitimate directories in network shares and USB drives and replace with malicious Windows Shortcut (LNK) files, resulting in the execution of arbitrary code retrieved from a command-and-control (C2) server.

    Cybersecurity

    To resolve its C2, GammaWorm initiates a GET request via curl to a hard-coded public Telegram channel. By using legitimate platforms like Telegram, the idea is to blend in with regular traffic, avoid detection, and sustain long-term espionage operations. GammaWorm also relies on NTFS Alternate Data Streams (ADS) technique to conceal its core modules.

    Another malware family delivered via GammaLoad is a modular information stealer codenamed GammaSteel that captures files matching certain extensions and exfiltrates them to an Amazon Web Services (AWS) S3 bucket or an attacker-controlled server as a fallback mechanism.

    Sekoia said the infection sequences could be used to distribute other malware families, such as GammaWipe (aka GamaWiper), depending on the threat actor’s objectives.

    “The exact deployment vector for GammaWorm remains ambiguous; it could be dropped concurrently by GammaLoad, or introduced independently via a user executing a weaponized USB drive,” it noted. “In addition, assessing the global execution flow, we assess with high confidence that GammaPhish is designed to deploy GammaLoad first.”

    Gamaredon, a Russian state-sponsored intrusion-set officially linked to the Federal Security Service (FSB), has a history of targeting Ukraine, particularly government, military, and critical infrastructure entities, using spear-phishing emails containing malicious attachments, in this booby-trapped RAR archives.

    Cybersecurity

    “This infection chain reveals a resilient, massive, and highly obfuscated modular design,” Sekoia said. “Because of its adaptability and the operator’s ability to update configurations on the fly, it is highly likely that this architecture will be reused in the future.”

    The development coincides with UAC-0184’s targeting of Ukrainian military-related targets to deliver an executable associated with a legitimate program called PassMark BurnInTest via LNK lures. A second threat activity cluster that has targeted Ukraine is UAC-0247 (previously tracked as UAC-0244), which has singled out drone operators to deploy HTML Application (HTA) droppers through ZIP archives and a backdoor capable of establishing a reverse shell to attacker-controlled infrastructure.

    Threat hunters have also charted the evolution of PixyNetLoader, a malware loader attributed to APT28 in connection with campaigns exploiting a Microsoft Office vulnerability (CVE-2026-21509), to extract a COVENANT Grunt implant. According to ExaTrack, the malware family has been detected in the wild since December 2024, with recent iterations discovered as recently as April 15, 2026.

    Deliver Exploits Gamaredon GammaSteel GammaWorm Ukraine WinRAR
    Follow on Google News Follow on Flipboard
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
    Previous ArticleTikTok influencer has a viral trick for buying thousand-dollar Home Depot items for just one penny—here’s how
    Next Article Meet Microsoft Scout, Your AI Coworker That Never Logs Off
    admin
    • Website

    Related Posts

    How Leading Organizations Are Turning EDR Into Operational Resilience

    June 2, 2026

    AI-Driven Exploitation is Destroying Vulnerability Management. Here’s How to Handle It.

    June 2, 2026

    Russia Is Showing Signs of Weakness in Ukraine. So It Hits Harder.

    June 2, 2026
    Leave A Reply Cancel Reply

    Demo
    Latest Posts

    Opinion | Tucker Carlson’s Big Bet

    California Election Live Updates: Primary Battles Could Set Direction for California and Congress

    Protests Grow in Albania Over Kushner-Linked Project

    How She Turned Her Beachside Cart Into a $332 Million Franchise

    Latest Posts

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    Advertisement
    Demo

    We are a digital news platform delivering timely, accurate, and insightful coverage of politics, global affairs, business, economy, sports, and more. Our mission is to keep readers informed with reliable news, clear analysis, and stories that truly matter.
    We're social. Connect with us:

    Facebook X (Twitter) Instagram Pinterest YouTube

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.

    Powered by
    ...
    ►
    Necessary cookies enable essential site features like secure log-ins and consent preference adjustments. They do not store personal data.
    None
    ►
    Functional cookies support features like content sharing on social media, collecting feedback, and enabling third-party tools.
    None
    ►
    Analytical cookies track visitor interactions, providing insights on metrics like visitor count, bounce rate, and traffic sources.
    None
    ►
    Advertisement cookies deliver personalized ads based on your previous visits and analyze the effectiveness of ad campaigns.
    None
    ►
    Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
    None
    Powered by