216.73.217.22

Analysis of Gamaredon campaign targeting Ukraine weaponizing CVE-2025-8088

· Published 19/06/2026 06:31

Export JSON

Essential information

Published
19/06/2026 06:31
Modified
Source / Author
AlienVault
Confidence
100/100
Report type(s)
threat-report
Labels / Tags
conscription-themed cve-2025-8088 gamaredon military-lures path-traversal persistence powershell ukraine winrar
Related entities
1 vulnerabilities (cve), 10 indicators, 1 intrusion sets (apt), 10 techniques (mitre)

Description

A campaign exploiting the path-traversal vulnerability has been actively targeting since February 2026, with ongoing activity through June 2026. The operation uses Ukrainian military and conscription-themed documents as lures, distributed as RAR archives. The malicious archives contain NTFS alternate data streams with path-traversal sequences that automatically place LNK files into the Windows Startup folder upon extraction. These shortcuts execute hidden stagers incorporating anti-analysis techniques including debugger checks, disk-space verification, and sleep delays to evade sandbox detection. The persistent nature of the attacks demonstrates continuous targeting of Ukrainian entities over a four-month period using social engineering focused on military documentation themes.

External references