Gamaredon Exploits WinRAR to Deliver GammaWorm and GammaSteel Against Ukraine
Gamaredon (Russia-nexus APT) is weaponizing CVE-2025-8088, a WinRAR path traversal flaw, to deliver GammaPhish HTA payloads that chain-load GammaWorm and GammaSteel against Ukrainian targets. The campaign focuses on credential harvesting and USB-based lateral propagation.
WinRAR path traversal flaws are evergreen APT entry points — patch WinRAR to 7.11+ immediately and block HTA execution via AppLocker or WDAC. If you have Ukrainian supply-chain exposure, treat any .rar attachment as hostile until verified out-of-band.
Gamaredon, Russia's FSB-linked threat actor, is actively exploiting CVE-2025-8088 — a path traversal bug in WinRAR — to drop GammaPhish, a malicious HTA file that acts as a first-stage loader against Ukrainian government and military targets.
GammaPhish retrieves GammaWorm, which propagates via removable drives, and GammaSteel, an infostealer focused on browser credentials and document exfiltration. The dual-payload design maximizes both reach and data-theft impact within air-gapped or segmented environments.
Defenders should prioritize WinRAR patching, disable Windows Script Host where feasible, and hunt for suspicious mshta.exe or wscript.exe child processes spawned from archive handlers — a reliable behavioral indicator of this chain.