NEWS Gamaredon's hackers have changed the album. Now they pack viruses into old ARJ archives to bypass antivirus

Gold Surfer

Administrator
Staff member
Administrator
Moon-Club
Exclusive
Infinity
Premium
Member
Joined
Jan 20, 2026
Messages
345
Reaction score
2,687
12 Gamaredon waves through one hole in WinRAR.
1778919355375.png
Gamaredon continues to attack Ukrainian state institutions through targeted phishing emails and vulnerability CVE-2025-8088 in WinRAR. The researchers found 12 bursts that have been going on since at least September 2025. The campaign remains active: the last letters in the sample date back to the end of April 2026, and in May the group has already switched to a new format of archives.

Gamaredon is also known as Aqua Blizzard, Primitive Bear, Shuckworm and UAC-0010. The group has been working almost exclusively on Ukrainian goals for many years. In the new campaign, state administrations, courts, prosecutors, law enforcement agencies, military units and regional units of the SBU came under attack. More often attacked not central offices, but regional and local institutions.

The chain of infection began with a letter similar to official notification. One example was sent on March 18, 2026 from the hacked mail of an official of the local administration in the Odessa region. The letter used a legal bait: the case number, the date of the incoming application, the name of the rapporteur judge and the document with the name “ship of the “convey”). The recipients were hidden in the BCC field, and the visible addresses of the sender and recipient matched.

The investment contained a RAR-archive with a name in the Ukrainian language that simulates the judicial subpoena. The archive operated CVE-2025-8088, the vulnerability of the way to bypass in WinRAR to version 7.13. When unpacking, the victim saw a PDF file with random characters, and the real VBS-booper GammaDrop was hiding in an alternative stream of data NTFS and recorded in the Windows autoloader folder.

The path within the archive was specially complicated by the recurring transitions between catalogs. Researchers believe that such a design could help circumvent the protection of WinRAR from path traversal. After unpacking, the PDF worked as a distracting file, and VBS was launched the next to the user's log in to the system.

The first stage was called GammaDrop. It is a heavily ostensified VBS file size of 78 KB. It downloads a remote GammaLoad HTA file with a C2 server on Cloudflare Workers, keeps it in a temporary directory and runs it. The address of the next stage is collected from the parameters of a particular campaign: the basic domain, ID mailings, paths, dates, suffix, random number and expansion.

For the wave of March 18, 2026, Cloudflare Workers-domain, ID campaign DvvsU-18-03, gate knife/bennet/juice, suffix admiration and .tif extension were used. In the April wave of logic, logic has been preserved, but the parameters have changed: the sample from April 27 used another Cloudflare Workers-domain, ID MouBig-27-04, the confer path, the sufix employee and the .bmp extension.

In some GammaDrop archives, it was generally missed: the malicious attachment immediately turned GammaLoad. The second stage was an 187-CB HTA file that was launched in a hidden window. Inside the HTA was VBScript, wrapped in HTML.

The island-based VBScript occupied approximately 4000-50000 lines, but after debuffication it was reduced to about 130 lines of work logic. GammaLoad was fixed in the system, collecting information about the infected computer, contacted C2 servers and waiting for the next load.

To fix GammaLoad used the RunOnce mechanism in the user Windows registry branch. This method allows you to run the saved script at the next user input, but does not require a separate service or driver.

The inner layer collected the computer name, the system disk and the volume serial number. This data turned into a victim identifier and transmitted to the control server inside the User-Agent header. In one of the samples, the string was disguised as a regular browser, and then added the device name, serial number and time mark.

The main C2 worked through the Cloudflare Workers, the backup channel used the RU domain, also hidden behind Cloudflare. Each iteration of the beacon created a new path with a random line and one of the predetermined extensions. Such a reception makes it difficult to filter one constant URL.

GammaLoad worked in the cycle and waited about 3.5 minutes between the appeals. At first, he contacted the main C2 and checked the response size. If the answer was too short or the server returned the 404 error, the malicious code waited 10 seconds and went to the backup server. The resulting load was performed inside the already running scenario process.

The option GammaLoad of April 27, 2026 changed the external signs, but retained the appointment. It used another User-Agent, other separators in the identifier string, a new victim name format, and a static tag instead of time. This option worked with one C2 and without a backup channel.

The mailings were about once a month. The earliest letter with the operation of CVE-2025-8088 dates back to September 26, 2025. First, the attachments were delivered to HTA files, in March 2026, the transition to VBS was noticed, and by the end of April there were VBScript files disguised as encoded VBScript with the .vbe extension.

Some of the letters were sent from hacked accounts of government agencies, police and judicial system. In other cases, the operator forged the sender through mail and stolen accounts. The scheme was often triggered due to the weak or incomplete setting of SPF, DKIM, and DMARC in the simulated domains.

One IP address from the subnet 194.58.66.0/24 was met in samples from December 2025 to April 2026. In December, a letter was sent through the relay server on behalf of the Office of the Prosecutor General of Ukraine. SPF was held for the relay domain, DKIM was absent, DMARC failed, but the domain policy was put up in quarantine, not backwards. The letter received an increased risk assessment, but reached the addressee.

In April, the same IP used stolen credentials from the Ukrainian hosting provider. The letters were disguised as CourtID and NABU and went to a sanatorium associated with the SBU. The SPF test took place, DKIM was absent, and DMARC was not performed for simulated domains because the necessary records were not published.

Other relay IPs from the same subnet appeared in September and August letters. In both cases, the stolen accounts of Ukrainian organizations and random HELO lines were used instead of normal host names.

A separate reception is associated with the parked domain of the former seller of mobile phones from partially occupied Zaporozhye region. In July 2025, he changed his email settings: added an MX and a soft SPF record for a legal mail relay. Researchers believe that the attackers gained access to the owner’s account from the registrar. Due to the old domain and legal relay, the emails were SPF and DKIM with a net rating.

In May 2026, Gamaredon again changed the packaging. In three waves on 5, 7 and 8, the group switched from RAR to ARJ archives disguised as .rar or .zip. They delivered GammaDrop HTA, which worked on the same logic: downloaded the next stage with Cloudflare Workers, Cloudflare quick tunnels or a new standalone domain. In ID campaigns, references to ARJ: ProbArjDev-08-05, GisArjUkr-07-05 and arjCF-05-05 appeared.

The infrastructure was built on quickly-time domains and legitimate services. In one chain used 3 Cloudflare-proxy hosts: the first delivered GammaLoad, the second took the GammaLoad beacon and gave the third stage, and the third worked as a backup C2. Letters Encrypt certificates were issued shortly before the phishing wave, and the infrastructure of the second stage was rotated after about a week.

For backup C2, a repetitive template is noticeable: the operator has registered domain pairs in the .ru and .online zones in one day, through a single registrar and with the same pair Cloudflare nameserver. This technique has been found in the Gamaredon infrastructure since at least September 2025.

In individual samples, the host check service was used to obtain current IP fast flux domains. There are also No-IP DDNS hosts. IP addresses for such domains did not last long and often served several malicious domains for one day.

Attribution to Gamaredon is based on a combination of features: Ukrainian state goals, large ovified VBS and HTA bootloaders, operation of CVE-2025-8088 through malicious archives, Cloudflare Workers, backup domains, quickx and repeated mail techniques. These elements coincide with the previously described campaigns of the group.

The main risk of the campaign is not limited to one vulnerability of WinRAR. Gamaredon uses real or hacked state accounts, weak mail authentication settings and topics familiar to Ukrainian institutions like bailiffs. Even after the closure of the CVE-2025-8088, the group has a working set of techniques: change archival formats, domains, extensions and downloader parameters, while maintaining the general chain of infection.
 
6,444Threads
87,319Messages
6,104Members
VoxiotLatest member
Top Bottom