{
  "actor_id": "Gamaredon",
  "attack_annotations": [
    {
      "name": "Spearphishing Attachment",
      "tactic": "Initial Access",
      "technique_id": "T1566.001"
    },
    {
      "name": "HTML Smuggling",
      "tactic": "Defense Evasion",
      "technique_id": "T1027.006"
    },
    {
      "name": "Exploitation for Client Execution (CVE-2025-8088 WinRAR)",
      "tactic": "Execution",
      "technique_id": "T1203"
    },
    {
      "name": "Registry Run Keys / Startup Folder",
      "tactic": "Persistence",
      "technique_id": "T1547.001"
    },
    {
      "name": "Mshta",
      "tactic": "Defense Evasion",
      "technique_id": "T1218.005"
    },
    {
      "name": "Visual Basic",
      "tactic": "Execution",
      "technique_id": "T1059.005"
    },
    {
      "name": "PowerShell (GammaSteel)",
      "tactic": "Execution",
      "technique_id": "T1059.001"
    },
    {
      "name": "NTFS File Attributes (Alternate Data Streams)",
      "tactic": "Defense Evasion",
      "technique_id": "T1564.004"
    },
    {
      "name": "Scheduled Task",
      "tactic": "Persistence",
      "technique_id": "T1053.005"
    },
    {
      "name": "Web Service: Dead Drop Resolver",
      "tactic": "Command and Control",
      "technique_id": "T1102.001"
    },
    {
      "name": "Application Layer Protocol: Web Protocols",
      "tactic": "Command and Control",
      "technique_id": "T1071.001"
    },
    {
      "name": "Replication Through Removable Media (USB)",
      "tactic": "Lateral Movement",
      "technique_id": "T1091"
    },
    {
      "name": "Exfiltration to Cloud Storage (S3-compatible)",
      "tactic": "Exfiltration",
      "technique_id": "T1567.002"
    }
  ],
  "chain": [
    {
      "entity_id": "e001",
      "review_notes": "HTML smuggling is endpoint defense-evasion (ATT&CK); modeled here only as the user-facing entry artifact.",
      "role": "entry",
      "role_confidence": "confirmed",
      "techniques": []
    },
    {
      "entity_id": "e002",
      "role": "staging",
      "role_confidence": "confirmed",
      "technique_confidence": "confirmed",
      "techniques": [
        "IIM-T024"
      ]
    },
    {
      "entity_id": "e003",
      "role": "staging",
      "role_confidence": "confirmed",
      "techniques": []
    },
    {
      "entity_id": "e004",
      "review_notes": "www.bbc.com path string is cosmetic log-blending, not a routing technique.",
      "role": "staging",
      "role_confidence": "confirmed",
      "techniques": []
    },
    {
      "entity_id": "e005",
      "review_notes": "GammaLoad updates its registry-cached C2 config via dead-drop resolvers before fetching further VBScript.",
      "role": "staging",
      "role_confidence": "confirmed",
      "technique_confidence": "confirmed",
      "techniques": [
        "IIM-T013"
      ]
    },
    {
      "entity_id": "e006",
      "role": "redirector",
      "role_confidence": "confirmed",
      "technique_confidence": "confirmed",
      "techniques": [
        "IIM-T013",
        "IIM-T006"
      ]
    },
    {
      "entity_id": "e007",
      "role": "redirector",
      "role_confidence": "confirmed",
      "technique_confidence": "confirmed",
      "techniques": [
        "IIM-T013",
        "IIM-T006"
      ]
    },
    {
      "entity_id": "e008",
      "role": "redirector",
      "role_confidence": "confirmed",
      "technique_confidence": "confirmed",
      "techniques": [
        "IIM-T013",
        "IIM-T006",
        "IIM-T018"
      ]
    },
    {
      "entity_id": "e009",
      "review_notes": "Single entity aggregating additional trusted-platform DDRs (Write.as, Rentry.co, Mastodon).",
      "role": "redirector",
      "role_confidence": "confirmed",
      "technique_confidence": "confirmed",
      "techniques": [
        "IIM-T013",
        "IIM-T006"
      ]
    },
    {
      "entity_id": "e010",
      "role": "redirector",
      "role_confidence": "confirmed",
      "technique_confidence": "confirmed",
      "techniques": [
        "IIM-T005",
        "IIM-T006"
      ]
    },
    {
      "entity_id": "e011",
      "review_notes": "Cloudflare quick tunnel as ephemeral front; T002 cloud-hosting tagging is the underlying Cloudflare substrate.",
      "role": "redirector",
      "role_confidence": "confirmed",
      "technique_confidence": "likely",
      "techniques": [
        "IIM-T005",
        "IIM-T002"
      ]
    },
    {
      "entity_id": "e012",
      "review_notes": "Disposable, rapidly rotated operator hosts (~24h lifespan, 55 in 12 days); dynamic-DNS (T008) inferred from the DDR/dynamic-DNS reporting and modeled as likely.",
      "role": "c2",
      "role_confidence": "confirmed",
      "technique_confidence": "likely",
      "techniques": [
        "IIM-T010",
        "IIM-T011",
        "IIM-T008"
      ]
    },
    {
      "entity_id": "e013",
      "role": "payload",
      "role_confidence": "confirmed",
      "techniques": []
    },
    {
      "entity_id": "e014",
      "role": "payload",
      "role_confidence": "confirmed",
      "techniques": []
    },
    {
      "entity_id": "e015",
      "review_notes": "S3-compatible exfiltration endpoint (trusted cloud storage) acting as the data-out C2 sink.",
      "role": "c2",
      "role_confidence": "confirmed",
      "technique_confidence": "confirmed",
      "techniques": [
        "IIM-T002",
        "IIM-T006"
      ]
    },
    {
      "entity_id": "e016",
      "review_notes": "Operator fallback exfiltration domains; rotation inferred from the broader high-frequency host-rotation pattern.",
      "role": "c2",
      "role_confidence": "confirmed",
      "technique_confidence": "likely",
      "techniques": [
        "IIM-T011"
      ]
    }
  ],
  "chain_id": "sekoia.2026.gamaredon-gammaworm-matryoshka-ddr-cloudflare-s3",
  "confidence": "confirmed",
  "description": "IIM chain for Sekoia.io's three-part 'FSB's matryoshka' Gamaredon series (parts 1-3, 1-4 June 2026) reconstructing a January 2026 infection chain. A weaponized xHTML lure HTML-smuggles a malicious RAR that exploits CVE-2025-8088 to drop a hidden HTA (GammaPhish) into Startup. The HTA runs mshta against an operator URL (padded with a www.bbc.com decoy path) to fetch GammaLoad, an in-memory VBScript loader cascade that resolves and registry-caches its C2 through dead-drop resolvers on graph.org/Telegra.ph, Teletype.in, public Telegram channels, Write.as, Rentry.co, Mastodon and Cloudflare Workers, with Cloudflare quick tunnels fronting the operator origin. The operator runs a rapidly rotated fleet of dedicated hosts (55 servers in 12 days, ~24h average lifespan) that serve VBScript and signal via HTTP 200/404. GammaLoad deploys GammaWorm (propagation) and GammaSteel (fileless PowerShell stealer), which exfiltrates documents to the S3-compatible Tebi.io/AWS S3 with fallback to hard-coded operator domains.",
  "entities": [
    {
      "evidence": [
        "Sekoia (#1) identified a cluster of weaponized xHTML files that use HTML smuggling to drop a malicious RAR archive on the victim.",
        "Assessed as the GammaPhish initial-access stage."
      ],
      "id": "e001",
      "observed_at": "2026-06-03T00:00:00Z",
      "source": "Sekoia.io TDR: FSB's matryoshka (#1 GammaPhish/GammaWorm 2026-06-01, #2 GammaLoad 2026-06-03, #3 GammaSteel 2026-06-04)",
      "type": "file",
      "value": "Weaponized xHTML lure (HTML smuggling), likely spear-phishing delivered",
      "x_reference_url": "https://blog.sekoia.io/fsbs-matryoshka-1-3-gamaredons-gifts-that-keeps-unpacking-gammaphish-and-gammaworm/"
    },
    {
      "evidence": [
        "Sekoia (#1) states the RAR exploits CVE-2025-8088 to extract a hidden HTA directly into the Windows Startup directory.",
        "Archive container delivery abusing a WinRAR path-traversal flaw for Startup-folder placement."
      ],
      "id": "e002",
      "observed_at": "2026-06-03T00:00:00Z",
      "source": "Sekoia.io TDR: FSB's matryoshka (#1 GammaPhish/GammaWorm 2026-06-01, #2 GammaLoad 2026-06-03, #3 GammaSteel 2026-06-04)",
      "type": "file",
      "value": "Malicious RAR archive exploiting CVE-2025-8088 (WinRAR path traversal)",
      "x_reference_url": "https://blog.sekoia.io/fsbs-matryoshka-1-3-gamaredons-gifts-that-keeps-unpacking-gammaphish-and-gammaworm/"
    },
    {
      "evidence": [
        "Sekoia (#1) states the RAR extracts a hidden HTA into Startup; the HTA runs mshta.exe with a URL whose path contains www.bbc.com to look legitimate in network logs."
      ],
      "id": "e003",
      "observed_at": "2026-06-03T00:00:00Z",
      "source": "Sekoia.io TDR: FSB's matryoshka (#1 GammaPhish/GammaWorm 2026-06-01, #2 GammaLoad 2026-06-03, #3 GammaSteel 2026-06-04)",
      "type": "file",
      "value": "Hidden HTA dropped into the Windows Startup directory (GammaPhish)",
      "x_reference_url": "https://blog.sekoia.io/fsbs-matryoshka-1-3-gamaredons-gifts-that-keeps-unpacking-gammaphish-and-gammaworm/"
    },
    {
      "evidence": [
        "Sekoia states the HTA runs mshta.exe against a URL embedding www.bbc.com in the path; that URL fetches the GammaLoad staging layer.",
        "The www.bbc.com string is cosmetic path padding to blend with normal logs, not a redirect through the BBC."
      ],
      "id": "e004",
      "observed_at": "2026-06-03T00:00:00Z",
      "source": "Sekoia.io TDR: FSB's matryoshka (#1 GammaPhish/GammaWorm 2026-06-01, #2 GammaLoad 2026-06-03, #3 GammaSteel 2026-06-04)",
      "type": "url",
      "value": "Operator mshta fetch URL with www.bbc.com decoy path -> retrieves GammaLoad",
      "x_reference_url": "https://blog.sekoia.io/fsbs-matryoshka-1-3-gamaredons-gifts-that-keeps-unpacking-gammaphish-and-gammaworm/"
    },
    {
      "evidence": [
        "Sekoia (#2) describes GammaLoad as a cascade of VBScript loaders executing loaders entirely in-memory, fingerprinting the host and updating C2 config in the registry (HKCU\\Console) via dead-drop resolvers."
      ],
      "id": "e005",
      "observed_at": "2026-06-03T00:00:00Z",
      "source": "Sekoia.io TDR: FSB's matryoshka (#1 GammaPhish/GammaWorm 2026-06-01, #2 GammaLoad 2026-06-03, #3 GammaSteel 2026-06-04)",
      "type": "file",
      "value": "GammaLoad VBScript loader cascade (4 in-memory stages; MD5 bf94f4056627907d86ce1cae8b44c67a observed)",
      "x_reference_url": "https://blog.sekoia.io/fsbs-matryoshka-2-3-gamaredons-gifts-that-keeps-unpacking-gammaload/"
    },
    {
      "evidence": [
        "Sekoia states the C2 resolution chain hops through graph.org, Cloudflare Workers, Teletype, Telegra.ph and Telegram before reaching an operator server; each resolved URL is written to the registry.",
        "Trusted publishing platform used as a dead-drop resolver hosting the current operational endpoint."
      ],
      "id": "e006",
      "observed_at": "2026-06-03T00:00:00Z",
      "source": "Sekoia.io TDR: FSB's matryoshka (#1 GammaPhish/GammaWorm 2026-06-01, #2 GammaLoad 2026-06-03, #3 GammaSteel 2026-06-04)",
      "type": "domain",
      "value": "graph.org (Telegra.ph / Teletype dead-drop resolver)",
      "x_reference_url": "https://blog.sekoia.io/fsbs-matryoshka-1-3-gamaredons-gifts-that-keeps-unpacking-gammaphish-and-gammaworm/"
    },
    {
      "evidence": [
        "Sekoia lists Teletype/Teletype.in among the dead-drop resolver platforms in the GammaWorm C2 resolution chain."
      ],
      "id": "e007",
      "observed_at": "2026-06-03T00:00:00Z",
      "source": "Sekoia.io TDR: FSB's matryoshka (#1 GammaPhish/GammaWorm 2026-06-01, #2 GammaLoad 2026-06-03, #3 GammaSteel 2026-06-04)",
      "type": "domain",
      "value": "teletype.in (dead-drop resolver)",
      "x_reference_url": "https://blog.sekoia.io/fsbs-matryoshka-1-3-gamaredons-gifts-that-keeps-unpacking-gammaphish-and-gammaworm/"
    },
    {
      "evidence": [
        "Sekoia states GammaWorm runs curl against a hard-coded public Telegram channel, parses the HTML for an obfuscated IP address, and posts the victim fingerprint back via randomized HTTP headers.",
        "Public Telegram channel abused as a third-party dead drop that publishes the active C2 IP."
      ],
      "id": "e008",
      "observed_at": "2026-06-03T00:00:00Z",
      "source": "Sekoia.io TDR: FSB's matryoshka (#1 GammaPhish/GammaWorm 2026-06-01, #2 GammaLoad 2026-06-03, #3 GammaSteel 2026-06-04)",
      "type": "url",
      "value": "Hard-coded public Telegram channel used as dead-drop resolver",
      "x_reference_url": "https://blog.sekoia.io/fsbs-matryoshka-1-3-gamaredons-gifts-that-keeps-unpacking-gammaphish-and-gammaworm/"
    },
    {
      "evidence": [
        "Sekoia (#3) lists dead-drop resolvers hosted on public platforms including Telegram, Telegra.ph, Write.as, Rentry.co and Mastodon, alongside dynamic DNS services.",
        "Modeled as one entity representing the additional trusted-platform DDRs observed across the infrastructure."
      ],
      "id": "e009",
      "observed_at": "2026-06-03T00:00:00Z",
      "source": "Sekoia.io TDR: FSB's matryoshka (#1 GammaPhish/GammaWorm 2026-06-01, #2 GammaLoad 2026-06-03, #3 GammaSteel 2026-06-04)",
      "type": "domain",
      "value": "write.as / rentry.co / mastodon (additional dead-drop resolver platforms)",
      "x_reference_url": "https://blog.sekoia.io/fsbs-matryoshka-3-3-gamaredons-gifts-that-keeps-unpacking-gammasteel/"
    },
    {
      "evidence": [
        "Sekoia states the resolution chain hops through Cloudflare Workers; Gamaredon also conceals staging servers behind Cloudflare quick tunnels.",
        "Serverless edge worker used as an ephemeral resolution/staging node."
      ],
      "id": "e010",
      "observed_at": "2026-06-03T00:00:00Z",
      "source": "Sekoia.io TDR: FSB's matryoshka (#1 GammaPhish/GammaWorm 2026-06-01, #2 GammaLoad 2026-06-03, #3 GammaSteel 2026-06-04)",
      "type": "domain",
      "value": "Cloudflare Workers subdomain (*.workers.dev) used in the resolution chain",
      "x_reference_url": "https://blog.sekoia.io/fsbs-matryoshka-1-3-gamaredons-gifts-that-keeps-unpacking-gammaphish-and-gammaworm/"
    },
    {
      "evidence": [
        "Sekoia and prior HarfangLab analysis describe Gamaredon's Telegraph/Teletype DDRs typically containing a Cloudflare quick-tunnel address; quick tunnels require no registration and blend with legitimate traffic.",
        "Ephemeral tunnel front concealing the operator-controlled origin."
      ],
      "id": "e011",
      "observed_at": "2026-06-03T00:00:00Z",
      "source": "Sekoia.io TDR: FSB's matryoshka (#1 GammaPhish/GammaWorm 2026-06-01, #2 GammaLoad 2026-06-03, #3 GammaSteel 2026-06-04)",
      "type": "url",
      "value": "Cloudflare quick tunnel (*.trycloudflare.com) concealing operator staging server",
      "x_reference_url": "https://blog.sekoia.io/fsbs-matryoshka-1-3-gamaredons-gifts-that-keeps-unpacking-gammaphish-and-gammaworm/"
    },
    {
      "evidence": [
        "Sekoia (#3) states the operator runs dedicated IPs/domains that receive victim fingerprints via HTTP headers and serve VBScript payloads / config updates; HTTP 200 = execute VBScript, HTTP 404 = config update.",
        "Sekoia mapped 55 new servers provisioned between 16 and 28 January 2026 with an average operational lifespan of ~24 hours, demonstrating high-frequency rotation. The single confirmed C2 IP and full network indicators are in the Sekoia Intelligence feed."
      ],
      "id": "e012",
      "observed_at": "2026-06-03T00:00:00Z",
      "source": "Sekoia.io TDR: FSB's matryoshka (#1 GammaPhish/GammaWorm 2026-06-01, #2 GammaLoad 2026-06-03, #3 GammaSteel 2026-06-04)",
      "type": "ip",
      "value": "Operator-controlled C2 server (dedicated IP/domain; 55 hosts provisioned 16-28 Jan 2026, ~24h average lifespan)",
      "x_reference_url": "https://blog.sekoia.io/fsbs-matryoshka-1-3-gamaredons-gifts-that-keeps-unpacking-gammaphish-and-gammaworm/"
    },
    {
      "evidence": [
        "Sekoia describes GammaWorm as the propagation component that resolves C2 via the dead-drop resolver chain, stores modules in NTFS ADS, and spreads via USB/network drives using malicious LNK shortcuts."
      ],
      "id": "e013",
      "observed_at": "2026-06-03T00:00:00Z",
      "source": "Sekoia.io TDR: FSB's matryoshka (#1 GammaPhish/GammaWorm 2026-06-01, #2 GammaLoad 2026-06-03, #3 GammaSteel 2026-06-04)",
      "type": "file",
      "value": "GammaWorm (VBScript worm, formerly LitterDrifter/PteroLNK/PterodoUSB; >20,000 lines)",
      "x_reference_url": "https://blog.sekoia.io/fsbs-matryoshka-1-3-gamaredons-gifts-that-keeps-unpacking-gammaphish-and-gammaworm/"
    },
    {
      "evidence": [
        "Sekoia (#3) describes GammaSteel as a modular PowerShell stealer staging 71 DPAPI-encrypted functions in the registry, hunting documents via drive scans, USB monitoring and active-edit surveillance."
      ],
      "id": "e014",
      "observed_at": "2026-06-03T00:00:00Z",
      "source": "Sekoia.io TDR: FSB's matryoshka (#1 GammaPhish/GammaWorm 2026-06-01, #2 GammaLoad 2026-06-03, #3 GammaSteel 2026-06-04)",
      "type": "file",
      "value": "GammaLoad-deployed GammaSteel (fileless PowerShell stealer; 71 DPAPI-encrypted functions in HKCU\\Printers)",
      "x_reference_url": "https://blog.sekoia.io/fsbs-matryoshka-3-3-gamaredons-gifts-that-keeps-unpacking-gammasteel/"
    },
    {
      "evidence": [
        "Sekoia (#3) states GammaSteel exfiltrates harvested documents to the legitimate S3-compatible service Tebi.io (and AWS S3), with fallback to hard-coded operator domains.",
        "Trusted S3-compatible cloud storage abused as the exfiltration endpoint."
      ],
      "id": "e015",
      "observed_at": "2026-06-03T00:00:00Z",
      "source": "Sekoia.io TDR: FSB's matryoshka (#1 GammaPhish/GammaWorm 2026-06-01, #2 GammaLoad 2026-06-03, #3 GammaSteel 2026-06-04)",
      "type": "domain",
      "value": "tebi.io (S3-compatible storage) / AWS S3 exfiltration endpoint",
      "x_reference_url": "https://blog.sekoia.io/fsbs-matryoshka-3-3-gamaredons-gifts-that-keeps-unpacking-gammasteel/"
    },
    {
      "evidence": [
        "Sekoia (#3) states GammaSteel falls back to hard-coded operator-controlled domains when the S3-compatible exfiltration path is unavailable."
      ],
      "id": "e016",
      "observed_at": "2026-06-03T00:00:00Z",
      "source": "Sekoia.io TDR: FSB's matryoshka (#1 GammaPhish/GammaWorm 2026-06-01, #2 GammaLoad 2026-06-03, #3 GammaSteel 2026-06-04)",
      "type": "domain",
      "value": "Hard-coded operator fallback domains (Russian-nexus) for exfiltration",
      "x_reference_url": "https://blog.sekoia.io/fsbs-matryoshka-3-3-gamaredons-gifts-that-keeps-unpacking-gammasteel/"
    }
  ],
  "iim_version": "1.1",
  "import_source": "manual-osint-report-to-iim-conversion",
  "name": "Gamaredon (UAC-0010) 'Gamma' matryoshka: WinRAR CVE-2025-8088 to multi-platform dead-drop resolvers",
  "needs_review": false,
  "observed_at": "2026-06-03T00:00:00Z",
  "relations": [
    {
      "confidence": "confirmed",
      "from": "e001",
      "sequence_order": 1,
      "to": "e002",
      "type": "drops",
      "x_evidence": "The weaponized xHTML uses HTML smuggling to drop the malicious RAR archive."
    },
    {
      "confidence": "confirmed",
      "from": "e002",
      "sequence_order": 2,
      "to": "e003",
      "type": "drops",
      "x_evidence": "The RAR exploits CVE-2025-8088 to extract a hidden HTA into the Windows Startup directory."
    },
    {
      "confidence": "confirmed",
      "from": "e003",
      "sequence_order": 3,
      "to": "e004",
      "type": "download",
      "x_evidence": "The HTA runs mshta.exe against the operator URL (with www.bbc.com decoy path) to fetch GammaLoad."
    },
    {
      "confidence": "confirmed",
      "from": "e004",
      "sequence_order": 4,
      "to": "e005",
      "type": "drops",
      "x_evidence": "The mshta fetch retrieves the GammaLoad VBScript staging layer."
    },
    {
      "confidence": "confirmed",
      "from": "e005",
      "sequence_order": 5,
      "to": "e006",
      "type": "references",
      "x_evidence": "GammaLoad/GammaWorm resolve C2 by hopping through graph.org (Telegra.ph) as a dead-drop resolver."
    },
    {
      "confidence": "confirmed",
      "from": "e005",
      "sequence_order": 6,
      "to": "e007",
      "type": "references",
      "x_evidence": "Teletype.in is part of the dead-drop resolver resolution chain."
    },
    {
      "confidence": "confirmed",
      "from": "e005",
      "sequence_order": 7,
      "to": "e008",
      "type": "references",
      "x_evidence": "GammaWorm runs curl against a hard-coded public Telegram channel and parses the HTML for the obfuscated C2 IP."
    },
    {
      "confidence": "confirmed",
      "from": "e005",
      "sequence_order": 8,
      "to": "e009",
      "type": "references",
      "x_evidence": "Additional trusted-platform dead-drop resolvers (Write.as, Rentry.co, Mastodon) are used across the infrastructure."
    },
    {
      "confidence": "confirmed",
      "from": "e005",
      "sequence_order": 9,
      "to": "e010",
      "type": "references",
      "x_evidence": "The resolution chain also hops through a Cloudflare Workers subdomain."
    },
    {
      "confidence": "likely",
      "from": "e010",
      "sequence_order": 10,
      "to": "e011",
      "type": "redirect",
      "x_evidence": "DDR entries typically contain a Cloudflare quick-tunnel address fronting the operator origin."
    },
    {
      "confidence": "confirmed",
      "from": "e006",
      "sequence_order": 11,
      "to": "e012",
      "type": "references",
      "x_evidence": "The Telegra.ph/graph.org dead-drop resolves to the current operator-controlled C2 server, written to HKCU\\Console."
    },
    {
      "confidence": "confirmed",
      "from": "e008",
      "sequence_order": 12,
      "to": "e012",
      "type": "references",
      "x_evidence": "The Telegram dead drop publishes the active operator C2 IP that GammaWorm extracts."
    },
    {
      "confidence": "likely",
      "from": "e011",
      "sequence_order": 13,
      "to": "e012",
      "type": "redirect",
      "x_evidence": "The Cloudflare quick tunnel forwards to the operator-controlled origin server."
    },
    {
      "confidence": "likely",
      "from": "e005",
      "sequence_order": 14,
      "to": "e013",
      "type": "drops",
      "x_evidence": "GammaWorm is assessed to be dropped concurrently by GammaLoad (or introduced via weaponized USB)."
    },
    {
      "confidence": "confirmed",
      "from": "e005",
      "sequence_order": 15,
      "to": "e014",
      "type": "drops",
      "x_evidence": "The GammaLoad cascade ultimately stages and executes GammaSteel."
    },
    {
      "confidence": "confirmed",
      "from": "e013",
      "sequence_order": 16,
      "to": "e012",
      "type": "connect",
      "x_evidence": "GammaWorm posts the host fingerprint to the operator C2 via randomized HTTP headers; HTTP 200 = execute VBScript, HTTP 404 = config update."
    },
    {
      "confidence": "confirmed",
      "from": "e014",
      "sequence_order": 17,
      "to": "e015",
      "type": "connect",
      "x_evidence": "GammaSteel exfiltrates harvested documents to the S3-compatible service Tebi.io / AWS S3."
    },
    {
      "confidence": "confirmed",
      "from": "e014",
      "sequence_order": 18,
      "to": "e016",
      "type": "connect",
      "x_evidence": "GammaSteel falls back to hard-coded operator domains when the S3-compatible exfiltration path is unavailable."
    }
  ],
  "title": "Gamaredon (UAC-0010) 'Gamma' matryoshka: WinRAR CVE-2025-8088 to multi-platform dead-drop resolvers, Cloudflare and S3 exfiltration",
  "x_iocs": {
    "cve": [
      "CVE-2025-8088"
    ],
    "dead_drop_resolver_platforms": [
      "graph.org",
      "telegra.ph",
      "teletype.in",
      "public Telegram channels",
      "write.as",
      "rentry.co",
      "mastodon (instances)",
      "*.workers.dev (Cloudflare Workers)",
      "*.trycloudflare.com (Cloudflare quick tunnels)",
      "dynamic DNS services"
    ],
    "exfiltration": [
      "tebi.io (S3-compatible)",
      "AWS S3",
      "hard-coded operator fallback domains"
    ],
    "infrastructure_note": [
      "55 operator hosts provisioned 16-28 Jan 2026, ~24h average lifespan; single confirmed C2 IP and full network indicators in the Sekoia Intelligence feed"
    ],
    "registry": [
      "HKCU\\Console (GammaWorm/GammaLoad C2 cache)",
      "HKCU\\Printers (GammaSteel 71 DPAPI modules)"
    ],
    "sample_md5": [
      "bf94f4056627907d86ce1cae8b44c67a (in-memory GammaLoad VBScript)"
    ]
  },
  "x_limitations": [
    "Sekoia publishes a subset of hundreds of IOCs; the complete network indicators (the confirmed operator C2 IP, additional domains/URLs) are distributed via the Sekoia Intelligence feed rather than in full in the blog, so the operator C2 entity is modeled generically.",
    "The dead-drop resolver platforms (e009) aggregate Write.as, Rentry.co and Mastodon into a single entity for readability; they can be split if per-URL granularity is needed.",
    "Dynamic-DNS abuse (IIM-T008) on the operator fleet is inferred from the reporting and modeled with likely confidence.",
    "Endpoint behavior (NTFS ADS module storage, DPAPI registry staging, USB/LNK propagation, scheduled-task persistence) is captured via ATT&CK/evidence rather than IIM techniques."
  ],
  "x_publication_safety": "TLP:CLEAR-style OSINT chain derived only from public Sekoia.io reporting; granular network IOCs deliberately not reproduced beyond what Sekoia published openly.",
  "x_report_published_at": "2026-06-01/2026-06-04 (three-part series)",
  "x_resource_links_verified": true,
  "x_selection_reason": "Exceptional IIM fit and unambiguous FSB attribution: archive-container delivery (WinRAR CVE-2025-8088), a layered dead-drop-resolver resolution chain across six+ trusted platforms, Cloudflare Workers/quick-tunnel ephemeral fronting, high-frequency disposable host rotation, and S3-compatible exfiltration. A near-complete tour of the IIM resolution/hosting/composition catalog and a strong reference for dead-drop-resolver modeling.",
  "x_source": "Sekoia.io Threat Detection & Research (TDR)",
  "x_source_title": "FSB's matryoshka - Gamaredon's gifts that keep unpacking (GammaPhish/GammaWorm, GammaLoad, GammaSteel)",
  "x_source_url": "https://blog.sekoia.io/fsbs-matryoshka-1-3-gamaredons-gifts-that-keeps-unpacking-gammaphish-and-gammaworm/",
  "x_source_urls": [
    "https://blog.sekoia.io/fsbs-matryoshka-1-3-gamaredons-gifts-that-keeps-unpacking-gammaphish-and-gammaworm/",
    "https://blog.sekoia.io/fsbs-matryoshka-2-3-gamaredons-gifts-that-keeps-unpacking-gammaload/",
    "https://blog.sekoia.io/fsbs-matryoshka-3-3-gamaredons-gifts-that-keeps-unpacking-gammasteel/"
  ]
}