Gamaredon
Russian state-sponsored (FSB) · Espionage / intelligence collection / disruption pre-positioning
Tactics, Techniques & Procedures (TTPs)
- HTML smuggling via weaponised XHTML attachments — evades email gateway attachment filtering
- CVE-2025-8088 WinRAR path traversal exploitation — archive extracts HTA to Startup folder without user interaction
- Gamma framework: GammaPhish (delivery), GammaLoad (staging), GammaWorm (USB propagation), GammaSteel (data theft), GammaWipe (destructive wiper)
- Telegram dead drop resolvers — current C2 IP stored in attacker-controlled Telegram channel, rotated to outpace blocklists
- Four-stage VBScript loader cascade — each stage fingerprints host, updates C2 config, fetches next stage
- Startup folder HTA persistence via mshta.exe with obfuscated URL arguments mimicking legitimate domains
Known Targets
Analyst Notes
Publicly attributed to Russia's FSB by Ukraine's Security Service (SBU) in 2021, with named FSB officers identified — an unusually specific public attribution. One of the most operationally active nation-state groups globally by campaign frequency. The 2026 Gamma framework represents a significant modularisation: individual components can be updated or withheld depending on the target and phase, and defenders detecting GammaLoad cannot assume intelligence on GammaSteel without recovering live payloads. CVE-2025-8088 was simultaneously exploited by Sandworm and Turla in the same timeframe, indicating rapid cross-operator exploit adoption within Russia's offensive ecosystem. Primary targeting is Ukraine, but organisations with Ukraine-related contacts represent elevated exposure.
Also Known As