Gamaredon Exploits WinRAR to Deliver GammaWorm and GammaSteel Against Ukraine

Summary

The Russian hacking group Gamaredon is exploiting a WinRAR vulnerability (CVE-2025-8088) to deliver malware like GammaWorm and GammaSteel against Ukraine. This activity aims at data theft and network propagation, utilizing an HTML Application payload called GammaPhish to retrieve further malicious content.

IFF Assessment

FOE

This article details the ongoing exploitation of a vulnerability by a known threat actor group, indicating an increased risk and active threat to targeted entities.

Severity

8.8 High

CISA KEV: Listed as actively exploited. Federal patch due: September 02, 2025. Known ransomware use: Unknown.

Defender Context

Defenders should be aware of Gamaredon's continued activity and their use of known vulnerabilities like CVE-2025-8088 in WinRAR. Organizations using WinRAR should prioritize patching this vulnerability and remain vigilant for suspicious files and network activity indicative of GammaWorm or GammaSteel malware.

Read Full Story →