PULSE NAME
FSB’s matryoshka #1/3 – Gamaredon’s gifts that keeps unpacking – GammaPhish and GammaWorm
WHITE Gamaredon AlienVault 2026-06-01 Modified: 2026-06-02
12
IOCs
MEDIUM VOLUME
Gamaredon, a cyberespionage group operated by Russia's FSB, conducts long-term intrusion operations targeting Ukrainian government, military, and critical infrastructure. This analysis documents their 2026 infection chain, which uses HTML smuggling with weaponized xHTML files delivering RAR archives that exploit CVE-2025-8088 to extract HTA files into Windows Startup directories. The chain deploys GammaPhish for initial access, GammaLoad for staging, GammaWorm for propagation via USB and network drives, and GammaSteal for exfiltration. The architecture is nearly fileless, leveraging NTFS Alternate Data Streams to conceal modules and using Dead Drop Resolvers on legitimate platforms like Telegram and Cloudflare for C2 infrastructure. Every stage functions as an independent backdoor capable of executing arbitrary VBScript, representing a shift from their historical Pteranodon framework to a modular ecosystem designed for persistent espionage.
Indicators of Compromise (12)
All CVE FileHash-MD5 IPv4 URL domain hostname
TYPEINDICATORDESCRIPTIONCREATED
CVE CVE-2018-20250 2026-06-01
CVE CVE-2025-8088 2026-06-01
FileHash-MD5 1794369214b7f62e70a0485e61335c61 2026-06-01
FileHash-MD5 8e1624d110c090ff57d4b493a9107c66 2026-06-01
IPv4 104.194.140.6 2026-06-01
URL https://efficiency-planes-emotions-fascinating.trycloudflare.com 2026-06-01
URL https://moment-cat-qld-place.trycloudflare.com/sylvilagus 2026-06-01
URL https://quitethepastry.ru 2026-06-01
domain quitethepastry.ru 2026-06-01
hostname iiwdsxwamylbwwsoyrmj.supabase.co 2026-06-01
hostname efficiency-planes-emotions-fascinating.trycloudflare.com 2026-06-01
hostname moment-cat-qld-place.trycloudflare.com 2026-06-01