216.73.216.6

FSB’s matryoshka #2/3 – Gamaredon’s gifts that keeps unpacking – GammaLoad

· Published 03/06/2026 13:18 · Modified 04/06/2026 08:40

Export JSON

Essential information

Published
03/06/2026 13:18
Modified
04/06/2026 08:40
Tags
2026-06-03 fsb gamaredon gammaload gammaphish gammasteel gammawipe gammaworm
Related entities
1 observables, 1 intrusion sets (apt), 19 techniques (mitre), 5 malware, 4 others

Description

, an -operated cyberespionage group, continues targeting Ukrainian government, military, and critical infrastructure through sophisticated multi-stage infection chains. This analysis examines , a collection of VBScript loaders that establish continuous access through three distinct stages. The malware leverages Dead Drop Resolvers on legitimate platforms including Telegram, Telegraph, and Check-Host to maintain persistent C2 communications while storing configurations in Windows registry keys. Each stage employs different techniques: the first fingerprints hosts and uses failover mechanisms, the second writes payloads to Alternate Data Streams and establishes persistence via scheduled tasks, and the third executes obfuscated PowerShell to deliver the final payload. This matryoshka architecture enables operators to deploy arbitrary payloads while remaining largely invisible by abusing trusted Windows features and cloud platforms.

External references