FSB’s matryoshka #2/3 – Gamaredon’s gifts that keeps unpacking – GammaLoad
Essential information
- Published
- 03/06/2026 13:18
- Modified
- 04/06/2026 08:40
- Tags
- 2026-06-03 fsb gamaredon gammaload gammaphish gammasteel gammawipe gammaworm
- Related entities
- 1 observables, 1 intrusion sets (apt), 19 techniques (mitre), 5 malware, 4 others
Description
Gamaredon, an FSB-operated cyberespionage group, continues targeting Ukrainian government, military, and critical infrastructure through sophisticated multi-stage infection chains. This analysis examines GammaLoad, a collection of VBScript loaders that establish continuous access through three distinct stages. The malware leverages Dead Drop Resolvers on legitimate platforms including Telegram, Telegraph, and Check-Host to maintain persistent C2 communications while storing configurations in Windows registry keys. Each stage employs different techniques: the first fingerprints hosts and uses failover mechanisms, the second writes payloads to Alternate Data Streams and establishes persistence via scheduled tasks, and the third executes obfuscated PowerShell to deliver the final GammaSteel payload. This matryoshka architecture enables operators to deploy arbitrary payloads while remaining largely invisible by abusing trusted Windows features and cloud platforms.