216.73.217.22

FSB’s matryoshka #1/3 – Gamaredon’s gifts that keeps unpacking – GammaPhish and GammaWorm

· Published 01/06/2026 19:31 · Modified 02/06/2026 09:30

Export JSON

Essential information

Published
01/06/2026 19:31
Modified
02/06/2026 09:30
Tags
2026-06-01 fsb gamaredon gammaload gammaphish gammasteal gammaworm pteranodon
Related entities
2 vulnerabilities (cve), 4 observables, 1 intrusion sets (apt), 19 techniques (mitre), 6 malware, 7 others

Description

, a cyberespionage group operated by Russia's , conducts long-term intrusion operations targeting Ukrainian government, military, and critical infrastructure. This analysis documents their 2026 infection chain, which uses HTML smuggling with weaponized xHTML files delivering RAR archives that exploit CVE-2025-8088 to extract HTA files into Windows Startup directories. The chain deploys for initial access, for staging, for propagation via USB and network drives, and for exfiltration. The architecture is nearly fileless, leveraging NTFS Alternate Data Streams to conceal modules and using Dead Drop Resolvers on legitimate platforms like Telegram and Cloudflare for C2 infrastructure. Every stage functions as an independent backdoor capable of executing arbitrary VBScript, representing a shift from their historical framework to a modular ecosystem designed for persistent espionage.

External references