sekoia.2026.gamaredon-gammaworm-matryoshka-ddr-cloudflare-s3
Gamaredon (UAC-0010) 'Gamma' matryoshka: WinRAR CVE-2025-8088 to multi-platform dead-drop resolvers
IIM chain for Sekoia.io's three-part 'FSB's matryoshka' Gamaredon series (parts 1-3, 1-4 June 2026) reconstructing a January 2026 infection chain. A weaponized xHTML lure HTML-smuggles a malicious RAR that exploits CVE-2025-8088 to drop a hidden HTA (GammaPhish) into Startup. The HTA runs mshta against an operator URL (padded with a www.bbc.com decoy path) to fetch GammaLoad, an in-memory VBScript loader cascade that resolves and registry-caches its C2 through dead-drop resolvers on graph.org/Telegra.ph, Teletype.in, public Telegram channels, Write.as, Rentry.co, Mastodon and Cloudflare Workers, with Cloudflare quick tunnels fronting the operator origin. The operator runs a rapidly rotated fleet of dedicated hosts (55 servers in 12 days, ~24h average lifespan) that serve VBScript and signal via HTTP 200/404. GammaLoad deploys GammaWorm (propagation) and GammaSteel (fileless PowerShell stealer), which exfiltrates documents to the S3-compatible Tebi.io/AWS S3 with fallback to hard-coded operator domains.
Infrastructure map
Role-based chain map
Chain storyline
ordered IIM positionsfile
Weaponized xHTML lure (HTML smuggling), likely spear-phishing delivered
file
Malicious RAR archive exploiting CVE-2025-8088 (WinRAR path traversal)
file
Hidden HTA dropped into the Windows Startup directory (GammaPhish)
url
Operator mshta fetch URL with www.bbc.com decoy path -> retrieves GammaLoad
file
GammaLoad VBScript loader cascade (4 in-memory stages; MD5 bf94f4056627907d86ce1cae8b44c67a observed)
domain
graph.org (Telegra.ph / Teletype dead-drop resolver)
domain
teletype.in (dead-drop resolver)
url
Hard-coded public Telegram channel used as dead-drop resolver
domain
write.as / rentry.co / mastodon (additional dead-drop resolver platforms)
domain
Cloudflare Workers subdomain (*.workers.dev) used in the resolution chain
url
Cloudflare quick tunnel (*.trycloudflare.com) concealing operator staging server
ip
Operator-controlled C2 server (dedicated IP/domain; 55 hosts provisioned 16-28 Jan 2026, ~24h average lifespan)
file
GammaWorm (VBScript worm, formerly LitterDrifter/PteroLNK/PterodoUSB; >20,000 lines)
file
GammaLoad-deployed GammaSteel (fileless PowerShell stealer; 71 DPAPI-encrypted functions in HKCU\Printers)
domain
tebi.io (S3-compatible storage) / AWS S3 exfiltration endpoint
domain
Hard-coded operator fallback domains (Russian-nexus) for exfiltration
Relations
directed infrastructure edgese001dropse002
confirmed
e002dropse003
confirmed
e003downloade004
confirmed
e004dropse005
confirmed
e005referencese006
confirmed
e005referencese007
confirmed
e005referencese008
confirmed
e005referencese009
confirmed
e005referencese010
confirmed
e010redirecte011
likely
e006referencese012
confirmed
e008referencese012
confirmed
e011redirecte012
likely
e005dropse013
likely
e005dropse014
confirmed
e013connecte012
confirmed
e014connecte015
confirmed
e014connecte016
confirmed
Entities & evidence
observable inventory| ID | Type | Value | Source / evidence |
|---|---|---|---|
e001 |
file | Weaponized xHTML lure (HTML smuggling), likely spear-phishing delivered |
https://blog.sekoia.io/fsbs-matryoshka-1-3-gamaredons-gifts-that-keeps-unpacking-gammaphish-and-gammaworm/
https://blog.sekoia.io/fsbs-matryoshka-2-3-gamaredons-gifts-that-keeps-unpacking-gammaload/
https://blog.sekoia.io/fsbs-matryoshka-3-3-gamaredons-gifts-that-keeps-unpacking-gammasteel/
Sekoia (#1) identified a cluster of weaponized xHTML files that use HTML smuggling to drop a malicious RAR archive on the victim. Assessed as the GammaPhish initial-access stage. |
e002 |
file | Malicious RAR archive exploiting CVE-2025-8088 (WinRAR path traversal) |
https://blog.sekoia.io/fsbs-matryoshka-1-3-gamaredons-gifts-that-keeps-unpacking-gammaphish-and-gammaworm/
https://blog.sekoia.io/fsbs-matryoshka-2-3-gamaredons-gifts-that-keeps-unpacking-gammaload/
https://blog.sekoia.io/fsbs-matryoshka-3-3-gamaredons-gifts-that-keeps-unpacking-gammasteel/
Sekoia (#1) states the RAR exploits CVE-2025-8088 to extract a hidden HTA directly into the Windows Startup directory. Archive container delivery abusing a WinRAR path-traversal flaw for Startup-folder placement. |
e003 |
file | Hidden HTA dropped into the Windows Startup directory (GammaPhish) |
https://blog.sekoia.io/fsbs-matryoshka-1-3-gamaredons-gifts-that-keeps-unpacking-gammaphish-and-gammaworm/
https://blog.sekoia.io/fsbs-matryoshka-2-3-gamaredons-gifts-that-keeps-unpacking-gammaload/
https://blog.sekoia.io/fsbs-matryoshka-3-3-gamaredons-gifts-that-keeps-unpacking-gammasteel/
Sekoia (#1) states the RAR extracts a hidden HTA into Startup; the HTA runs mshta.exe with a URL whose path contains www.bbc.com to look legitimate in network logs. |
e004 |
url | Operator mshta fetch URL with www.bbc.com decoy path -> retrieves GammaLoad |
https://blog.sekoia.io/fsbs-matryoshka-1-3-gamaredons-gifts-that-keeps-unpacking-gammaphish-and-gammaworm/
https://blog.sekoia.io/fsbs-matryoshka-2-3-gamaredons-gifts-that-keeps-unpacking-gammaload/
https://blog.sekoia.io/fsbs-matryoshka-3-3-gamaredons-gifts-that-keeps-unpacking-gammasteel/
Sekoia states the HTA runs mshta.exe against a URL embedding www.bbc.com in the path; that URL fetches the GammaLoad staging layer. The www.bbc.com string is cosmetic path padding to blend with normal logs, not a redirect through the BBC. |
e005 |
file | GammaLoad VBScript loader cascade (4 in-memory stages; MD5 bf94f4056627907d86ce1cae8b44c67a observed) |
https://blog.sekoia.io/fsbs-matryoshka-1-3-gamaredons-gifts-that-keeps-unpacking-gammaphish-and-gammaworm/
https://blog.sekoia.io/fsbs-matryoshka-2-3-gamaredons-gifts-that-keeps-unpacking-gammaload/
https://blog.sekoia.io/fsbs-matryoshka-3-3-gamaredons-gifts-that-keeps-unpacking-gammasteel/
Sekoia (#2) describes GammaLoad as a cascade of VBScript loaders executing loaders entirely in-memory, fingerprinting the host and updating C2 config in the registry (HKCU\Console) via dead-drop resolvers. |
e006 |
domain | graph.org (Telegra.ph / Teletype dead-drop resolver) |
https://blog.sekoia.io/fsbs-matryoshka-1-3-gamaredons-gifts-that-keeps-unpacking-gammaphish-and-gammaworm/
https://blog.sekoia.io/fsbs-matryoshka-2-3-gamaredons-gifts-that-keeps-unpacking-gammaload/
https://blog.sekoia.io/fsbs-matryoshka-3-3-gamaredons-gifts-that-keeps-unpacking-gammasteel/
Sekoia states the C2 resolution chain hops through graph.org, Cloudflare Workers, Teletype, Telegra.ph and Telegram before reaching an operator server; each resolved URL is written to the registry. Trusted publishing platform used as a dead-drop resolver hosting the current operational endpoint. |
e007 |
domain | teletype.in (dead-drop resolver) |
https://blog.sekoia.io/fsbs-matryoshka-1-3-gamaredons-gifts-that-keeps-unpacking-gammaphish-and-gammaworm/
https://blog.sekoia.io/fsbs-matryoshka-2-3-gamaredons-gifts-that-keeps-unpacking-gammaload/
https://blog.sekoia.io/fsbs-matryoshka-3-3-gamaredons-gifts-that-keeps-unpacking-gammasteel/
Sekoia lists Teletype/Teletype.in among the dead-drop resolver platforms in the GammaWorm C2 resolution chain. |
e008 |
url | Hard-coded public Telegram channel used as dead-drop resolver |
https://blog.sekoia.io/fsbs-matryoshka-1-3-gamaredons-gifts-that-keeps-unpacking-gammaphish-and-gammaworm/
https://blog.sekoia.io/fsbs-matryoshka-2-3-gamaredons-gifts-that-keeps-unpacking-gammaload/
https://blog.sekoia.io/fsbs-matryoshka-3-3-gamaredons-gifts-that-keeps-unpacking-gammasteel/
Sekoia states GammaWorm runs curl against a hard-coded public Telegram channel, parses the HTML for an obfuscated IP address, and posts the victim fingerprint back via randomized HTTP headers. Public Telegram channel abused as a third-party dead drop that publishes the active C2 IP. |
e009 |
domain | write.as / rentry.co / mastodon (additional dead-drop resolver platforms) |
https://blog.sekoia.io/fsbs-matryoshka-1-3-gamaredons-gifts-that-keeps-unpacking-gammaphish-and-gammaworm/
https://blog.sekoia.io/fsbs-matryoshka-2-3-gamaredons-gifts-that-keeps-unpacking-gammaload/
https://blog.sekoia.io/fsbs-matryoshka-3-3-gamaredons-gifts-that-keeps-unpacking-gammasteel/
Sekoia (#3) lists dead-drop resolvers hosted on public platforms including Telegram, Telegra.ph, Write.as, Rentry.co and Mastodon, alongside dynamic DNS services. Modeled as one entity representing the additional trusted-platform DDRs observed across the infrastructure. |
e010 |
domain | Cloudflare Workers subdomain (*.workers.dev) used in the resolution chain |
https://blog.sekoia.io/fsbs-matryoshka-1-3-gamaredons-gifts-that-keeps-unpacking-gammaphish-and-gammaworm/
https://blog.sekoia.io/fsbs-matryoshka-2-3-gamaredons-gifts-that-keeps-unpacking-gammaload/
https://blog.sekoia.io/fsbs-matryoshka-3-3-gamaredons-gifts-that-keeps-unpacking-gammasteel/
Sekoia states the resolution chain hops through Cloudflare Workers; Gamaredon also conceals staging servers behind Cloudflare quick tunnels. Serverless edge worker used as an ephemeral resolution/staging node. |
e011 |
url | Cloudflare quick tunnel (*.trycloudflare.com) concealing operator staging server |
https://blog.sekoia.io/fsbs-matryoshka-1-3-gamaredons-gifts-that-keeps-unpacking-gammaphish-and-gammaworm/
https://blog.sekoia.io/fsbs-matryoshka-2-3-gamaredons-gifts-that-keeps-unpacking-gammaload/
https://blog.sekoia.io/fsbs-matryoshka-3-3-gamaredons-gifts-that-keeps-unpacking-gammasteel/
Sekoia and prior HarfangLab analysis describe Gamaredon's Telegraph/Teletype DDRs typically containing a Cloudflare quick-tunnel address; quick tunnels require no registration and blend with legitimate traffic. Ephemeral tunnel front concealing the operator-controlled origin. |
e012 |
ip | Operator-controlled C2 server (dedicated IP/domain; 55 hosts provisioned 16-28 Jan 2026, ~24h average lifespan) |
https://blog.sekoia.io/fsbs-matryoshka-1-3-gamaredons-gifts-that-keeps-unpacking-gammaphish-and-gammaworm/
https://blog.sekoia.io/fsbs-matryoshka-2-3-gamaredons-gifts-that-keeps-unpacking-gammaload/
https://blog.sekoia.io/fsbs-matryoshka-3-3-gamaredons-gifts-that-keeps-unpacking-gammasteel/
Sekoia (#3) states the operator runs dedicated IPs/domains that receive victim fingerprints via HTTP headers and serve VBScript payloads / config updates; HTTP 200 = execute VBScript, HTTP 404 = config update. Sekoia mapped 55 new servers provisioned between 16 and 28 January 2026 with an average operational lifespan of ~24 hours, demonstrating high-frequency rotation. The single confirmed C2 IP and full network indicators are in the Sekoia Intelligence feed. |
e013 |
file | GammaWorm (VBScript worm, formerly LitterDrifter/PteroLNK/PterodoUSB; >20,000 lines) |
https://blog.sekoia.io/fsbs-matryoshka-1-3-gamaredons-gifts-that-keeps-unpacking-gammaphish-and-gammaworm/
https://blog.sekoia.io/fsbs-matryoshka-2-3-gamaredons-gifts-that-keeps-unpacking-gammaload/
https://blog.sekoia.io/fsbs-matryoshka-3-3-gamaredons-gifts-that-keeps-unpacking-gammasteel/
Sekoia describes GammaWorm as the propagation component that resolves C2 via the dead-drop resolver chain, stores modules in NTFS ADS, and spreads via USB/network drives using malicious LNK shortcuts. |
e014 |
file | GammaLoad-deployed GammaSteel (fileless PowerShell stealer; 71 DPAPI-encrypted functions in HKCU\Printers) |
https://blog.sekoia.io/fsbs-matryoshka-1-3-gamaredons-gifts-that-keeps-unpacking-gammaphish-and-gammaworm/
https://blog.sekoia.io/fsbs-matryoshka-2-3-gamaredons-gifts-that-keeps-unpacking-gammaload/
https://blog.sekoia.io/fsbs-matryoshka-3-3-gamaredons-gifts-that-keeps-unpacking-gammasteel/
Sekoia (#3) describes GammaSteel as a modular PowerShell stealer staging 71 DPAPI-encrypted functions in the registry, hunting documents via drive scans, USB monitoring and active-edit surveillance. |
e015 |
domain | tebi.io (S3-compatible storage) / AWS S3 exfiltration endpoint |
https://blog.sekoia.io/fsbs-matryoshka-1-3-gamaredons-gifts-that-keeps-unpacking-gammaphish-and-gammaworm/
https://blog.sekoia.io/fsbs-matryoshka-2-3-gamaredons-gifts-that-keeps-unpacking-gammaload/
https://blog.sekoia.io/fsbs-matryoshka-3-3-gamaredons-gifts-that-keeps-unpacking-gammasteel/
Sekoia (#3) states GammaSteel exfiltrates harvested documents to the legitimate S3-compatible service Tebi.io (and AWS S3), with fallback to hard-coded operator domains. Trusted S3-compatible cloud storage abused as the exfiltration endpoint. |
e016 |
domain | Hard-coded operator fallback domains (Russian-nexus) for exfiltration |
https://blog.sekoia.io/fsbs-matryoshka-1-3-gamaredons-gifts-that-keeps-unpacking-gammaphish-and-gammaworm/
https://blog.sekoia.io/fsbs-matryoshka-2-3-gamaredons-gifts-that-keeps-unpacking-gammaload/
https://blog.sekoia.io/fsbs-matryoshka-3-3-gamaredons-gifts-that-keeps-unpacking-gammasteel/
Sekoia (#3) states GammaSteel falls back to hard-coded operator-controlled domains when the S3-compatible exfiltration path is unavailable. |
ATT&CK annotations
optional complementary mappingRaw IIM JSON canonical body from MANTIS expand
{
"actor_id": "Gamaredon",
"attack_annotations": [
{
"name": "Spearphishing Attachment",
"tactic": "Initial Access",
"technique_id": "T1566.001"
},
{
"name": "HTML Smuggling",
"tactic": "Defense Evasion",
"technique_id": "T1027.006"
},
{
"name": "Exploitation for Client Execution (CVE-2025-8088 WinRAR)",
"tactic": "Execution",
"technique_id": "T1203"
},
{
"name": "Registry Run Keys / Startup Folder",
"tactic": "Persistence",
"technique_id": "T1547.001"
},
{
"name": "Mshta",
"tactic": "Defense Evasion",
"technique_id": "T1218.005"
},
{
"name": "Visual Basic",
"tactic": "Execution",
"technique_id": "T1059.005"
},
{
"name": "PowerShell (GammaSteel)",
"tactic": "Execution",
"technique_id": "T1059.001"
},
{
"name": "NTFS File Attributes (Alternate Data Streams)",
"tactic": "Defense Evasion",
"technique_id": "T1564.004"
},
{
"name": "Scheduled Task",
"tactic": "Persistence",
"technique_id": "T1053.005"
},
{
"name": "Web Service: Dead Drop Resolver",
"tactic": "Command and Control",
"technique_id": "T1102.001"
},
{
"name": "Application Layer Protocol: Web Protocols",
"tactic": "Command and Control",
"technique_id": "T1071.001"
},
{
"name": "Replication Through Removable Media (USB)",
"tactic": "Lateral Movement",
"technique_id": "T1091"
},
{
"name": "Exfiltration to Cloud Storage (S3-compatible)",
"tactic": "Exfiltration",
"technique_id": "T1567.002"
}
],
"chain": [
{
"entity_id": "e001",
"review_notes": "HTML smuggling is endpoint defense-evasion (ATT&CK); modeled here only as the user-facing entry artifact.",
"role": "entry",
"role_confidence": "confirmed",
"techniques": []
},
{
"entity_id": "e002",
"role": "staging",
"role_confidence": "confirmed",
"technique_confidence": "confirmed",
"techniques": [
"IIM-T024"
]
},
{
"entity_id": "e003",
"role": "staging",
"role_confidence": "confirmed",
"techniques": []
},
{
"entity_id": "e004",
"review_notes": "www.bbc.com path string is cosmetic log-blending, not a routing technique.",
"role": "staging",
"role_confidence": "confirmed",
"techniques": []
},
{
"entity_id": "e005",
"review_notes": "GammaLoad updates its registry-cached C2 config via dead-drop resolvers before fetching further VBScript.",
"role": "staging",
"role_confidence": "confirmed",
"technique_confidence": "confirmed",
"techniques": [
"IIM-T013"
]
},
{
"entity_id": "e006",
"role": "redirector",
"role_confidence": "confirmed",
"technique_confidence": "confirmed",
"techniques": [
"IIM-T013",
"IIM-T006"
]
},
{
"entity_id": "e007",
"role": "redirector",
"role_confidence": "confirmed",
"technique_confidence": "confirmed",
"techniques": [
"IIM-T013",
"IIM-T006"
]
},
{
"entity_id": "e008",
"role": "redirector",
"role_confidence": "confirmed",
"technique_confidence": "confirmed",
"techniques": [
"IIM-T013",
"IIM-T006",
"IIM-T018"
]
},
{
"entity_id": "e009",
"review_notes": "Single entity aggregating additional trusted-platform DDRs (Write.as, Rentry.co, Mastodon).",
"role": "redirector",
"role_confidence": "confirmed",
"technique_confidence": "confirmed",
"techniques": [
"IIM-T013",
"IIM-T006"
]
},
{
"entity_id": "e010",
"role": "redirector",
"role_confidence": "confirmed",
"technique_confidence": "confirmed",
"techniques": [
"IIM-T005",
"IIM-T006"
]
},
{
"entity_id": "e011",
"review_notes": "Cloudflare quick tunnel as ephemeral front; T002 cloud-hosting tagging is the underlying Cloudflare substrate.",
"role": "redirector",
"role_confidence": "confirmed",
"technique_confidence": "likely",
"techniques": [
"IIM-T005",
"IIM-T002"
]
},
{
"entity_id": "e012",
"review_notes": "Disposable, rapidly rotated operator hosts (~24h lifespan, 55 in 12 days); dynamic-DNS (T008) inferred from the DDR/dynamic-DNS reporting and modeled as likely.",
"role": "c2",
"role_confidence": "confirmed",
"technique_confidence": "likely",
"techniques": [
"IIM-T010",
"IIM-T011",
"IIM-T008"
]
},
{
"entity_id": "e013",
"role": "payload",
"role_confidence": "confirmed",
"techniques": []
},
{
"entity_id": "e014",
"role": "payload",
"role_confidence": "confirmed",
"techniques": []
},
{
"entity_id": "e015",
"review_notes": "S3-compatible exfiltration endpoint (trusted cloud storage) acting as the data-out C2 sink.",
"role": "c2",
"role_confidence": "confirmed",
"technique_confidence": "confirmed",
"techniques": [
"IIM-T002",
"IIM-T006"
]
},
{
"entity_id": "e016",
"review_notes": "Operator fallback exfiltration domains; rotation inferred from the broader high-frequency host-rotation pattern.",
"role": "c2",
"role_confidence": "confirmed",
"technique_confidence": "likely",
"techniques": [
"IIM-T011"
]
}
],
"chain_id": "sekoia.2026.gamaredon-gammaworm-matryoshka-ddr-cloudflare-s3",
"confidence": "confirmed",
"description": "IIM chain for Sekoia.io's three-part 'FSB's matryoshka' Gamaredon series (parts 1-3, 1-4 June 2026) reconstructing a January 2026 infection chain. A weaponized xHTML lure HTML-smuggles a malicious RAR that exploits CVE-2025-8088 to drop a hidden HTA (GammaPhish) into Startup. The HTA runs mshta against an operator URL (padded with a www.bbc.com decoy path) to fetch GammaLoad, an in-memory VBScript loader cascade that resolves and registry-caches its C2 through dead-drop resolvers on graph.org/Telegra.ph, Teletype.in, public Telegram channels, Write.as, Rentry.co, Mastodon and Cloudflare Workers, with Cloudflare quick tunnels fronting the operator origin. The operator runs a rapidly rotated fleet of dedicated hosts (55 servers in 12 days, ~24h average lifespan) that serve VBScript and signal via HTTP 200/404. GammaLoad deploys GammaWorm (propagation) and GammaSteel (fileless PowerShell stealer), which exfiltrates documents to the S3-compatible Tebi.io/AWS S3 with fallback to hard-coded operator domains.",
"entities": [
{
"evidence": [
"Sekoia (#1) identified a cluster of weaponized xHTML files that use HTML smuggling to drop a malicious RAR archive on the victim.",
"Assessed as the GammaPhish initial-access stage."
],
"id": "e001",
"observed_at": "2026-06-03T00:00:00Z",
"source": "Sekoia.io TDR: FSB's matryoshka (#1 GammaPhish/GammaWorm 2026-06-01, #2 GammaLoad 2026-06-03, #3 GammaSteel 2026-06-04)",
"type": "file",
"value": "Weaponized xHTML lure (HTML smuggling), likely spear-phishing delivered",
"x_reference_url": "https://blog.sekoia.io/fsbs-matryoshka-1-3-gamaredons-gifts-that-keeps-unpacking-gammaphish-and-gammaworm/"
},
{
"evidence": [
"Sekoia (#1) states the RAR exploits CVE-2025-8088 to extract a hidden HTA directly into the Windows Startup directory.",
"Archive container delivery abusing a WinRAR path-traversal flaw for Startup-folder placement."
],
"id": "e002",
"observed_at": "2026-06-03T00:00:00Z",
"source": "Sekoia.io TDR: FSB's matryoshka (#1 GammaPhish/GammaWorm 2026-06-01, #2 GammaLoad 2026-06-03, #3 GammaSteel 2026-06-04)",
"type": "file",
"value": "Malicious RAR archive exploiting CVE-2025-8088 (WinRAR path traversal)",
"x_reference_url": "https://blog.sekoia.io/fsbs-matryoshka-1-3-gamaredons-gifts-that-keeps-unpacking-gammaphish-and-gammaworm/"
},
{
"evidence": [
"Sekoia (#1) states the RAR extracts a hidden HTA into Startup; the HTA runs mshta.exe with a URL whose path contains www.bbc.com to look legitimate in network logs."
],
"id": "e003",
"observed_at": "2026-06-03T00:00:00Z",
"source": "Sekoia.io TDR: FSB's matryoshka (#1 GammaPhish/GammaWorm 2026-06-01, #2 GammaLoad 2026-06-03, #3 GammaSteel 2026-06-04)",
"type": "file",
"value": "Hidden HTA dropped into the Windows Startup directory (GammaPhish)",
"x_reference_url": "https://blog.sekoia.io/fsbs-matryoshka-1-3-gamaredons-gifts-that-keeps-unpacking-gammaphish-and-gammaworm/"
},
{
"evidence": [
"Sekoia states the HTA runs mshta.exe against a URL embedding www.bbc.com in the path; that URL fetches the GammaLoad staging layer.",
"The www.bbc.com string is cosmetic path padding to blend with normal logs, not a redirect through the BBC."
],
"id": "e004",
"observed_at": "2026-06-03T00:00:00Z",
"source": "Sekoia.io TDR: FSB's matryoshka (#1 GammaPhish/GammaWorm 2026-06-01, #2 GammaLoad 2026-06-03, #3 GammaSteel 2026-06-04)",
"type": "url",
"value": "Operator mshta fetch URL with www.bbc.com decoy path -> retrieves GammaLoad",
"x_reference_url": "https://blog.sekoia.io/fsbs-matryoshka-1-3-gamaredons-gifts-that-keeps-unpacking-gammaphish-and-gammaworm/"
},
{
"evidence": [
"Sekoia (#2) describes GammaLoad as a cascade of VBScript loaders executing loaders entirely in-memory, fingerprinting the host and updating C2 config in the registry (HKCU\\Console) via dead-drop resolvers."
],
"id": "e005",
"observed_at": "2026-06-03T00:00:00Z",
"source": "Sekoia.io TDR: FSB's matryoshka (#1 GammaPhish/GammaWorm 2026-06-01, #2 GammaLoad 2026-06-03, #3 GammaSteel 2026-06-04)",
"type": "file",
"value": "GammaLoad VBScript loader cascade (4 in-memory stages; MD5 bf94f4056627907d86ce1cae8b44c67a observed)",
"x_reference_url": "https://blog.sekoia.io/fsbs-matryoshka-2-3-gamaredons-gifts-that-keeps-unpacking-gammaload/"
},
{
"evidence": [
"Sekoia states the C2 resolution chain hops through graph.org, Cloudflare Workers, Teletype, Telegra.ph and Telegram before reaching an operator server; each resolved URL is written to the registry.",
"Trusted publishing platform used as a dead-drop resolver hosting the current operational endpoint."
],
"id": "e006",
"observed_at": "2026-06-03T00:00:00Z",
"source": "Sekoia.io TDR: FSB's matryoshka (#1 GammaPhish/GammaWorm 2026-06-01, #2 GammaLoad 2026-06-03, #3 GammaSteel 2026-06-04)",
"type": "domain",
"value": "graph.org (Telegra.ph / Teletype dead-drop resolver)",
"x_reference_url": "https://blog.sekoia.io/fsbs-matryoshka-1-3-gamaredons-gifts-that-keeps-unpacking-gammaphish-and-gammaworm/"
},
{
"evidence": [
"Sekoia lists Teletype/Teletype.in among the dead-drop resolver platforms in the GammaWorm C2 resolution chain."
],
"id": "e007",
"observed_at": "2026-06-03T00:00:00Z",
"source": "Sekoia.io TDR: FSB's matryoshka (#1 GammaPhish/GammaWorm 2026-06-01, #2 GammaLoad 2026-06-03, #3 GammaSteel 2026-06-04)",
"type": "domain",
"value": "teletype.in (dead-drop resolver)",
"x_reference_url": "https://blog.sekoia.io/fsbs-matryoshka-1-3-gamaredons-gifts-that-keeps-unpacking-gammaphish-and-gammaworm/"
},
{
"evidence": [
"Sekoia states GammaWorm runs curl against a hard-coded public Telegram channel, parses the HTML for an obfuscated IP address, and posts the victim fingerprint back via randomized HTTP headers.",
"Public Telegram channel abused as a third-party dead drop that publishes the active C2 IP."
],
"id": "e008",
"observed_at": "2026-06-03T00:00:00Z",
"source": "Sekoia.io TDR: FSB's matryoshka (#1 GammaPhish/GammaWorm 2026-06-01, #2 GammaLoad 2026-06-03, #3 GammaSteel 2026-06-04)",
"type": "url",
"value": "Hard-coded public Telegram channel used as dead-drop resolver",
"x_reference_url": "https://blog.sekoia.io/fsbs-matryoshka-1-3-gamaredons-gifts-that-keeps-unpacking-gammaphish-and-gammaworm/"
},
{
"evidence": [
"Sekoia (#3) lists dead-drop resolvers hosted on public platforms including Telegram, Telegra.ph, Write.as, Rentry.co and Mastodon, alongside dynamic DNS services.",
"Modeled as one entity representing the additional trusted-platform DDRs observed across the infrastructure."
],
"id": "e009",
"observed_at": "2026-06-03T00:00:00Z",
"source": "Sekoia.io TDR: FSB's matryoshka (#1 GammaPhish/GammaWorm 2026-06-01, #2 GammaLoad 2026-06-03, #3 GammaSteel 2026-06-04)",
"type": "domain",
"value": "write.as / rentry.co / mastodon (additional dead-drop resolver platforms)",
"x_reference_url": "https://blog.sekoia.io/fsbs-matryoshka-3-3-gamaredons-gifts-that-keeps-unpacking-gammasteel/"
},
{
"evidence": [
"Sekoia states the resolution chain hops through Cloudflare Workers; Gamaredon also conceals staging servers behind Cloudflare quick tunnels.",
"Serverless edge worker used as an ephemeral resolution/staging node."
],
"id": "e010",
"observed_at": "2026-06-03T00:00:00Z",
"source": "Sekoia.io TDR: FSB's matryoshka (#1 GammaPhish/GammaWorm 2026-06-01, #2 GammaLoad 2026-06-03, #3 GammaSteel 2026-06-04)",
"type": "domain",
"value": "Cloudflare Workers subdomain (*.workers.dev) used in the resolution chain",
"x_reference_url": "https://blog.sekoia.io/fsbs-matryoshka-1-3-gamaredons-gifts-that-keeps-unpacking-gammaphish-and-gammaworm/"
},
{
"evidence": [
"Sekoia and prior HarfangLab analysis describe Gamaredon's Telegraph/Teletype DDRs typically containing a Cloudflare quick-tunnel address; quick tunnels require no registration and blend with legitimate traffic.",
"Ephemeral tunnel front concealing the operator-controlled origin."
],
"id": "e011",
"observed_at": "2026-06-03T00:00:00Z",
"source": "Sekoia.io TDR: FSB's matryoshka (#1 GammaPhish/GammaWorm 2026-06-01, #2 GammaLoad 2026-06-03, #3 GammaSteel 2026-06-04)",
"type": "url",
"value": "Cloudflare quick tunnel (*.trycloudflare.com) concealing operator staging server",
"x_reference_url": "https://blog.sekoia.io/fsbs-matryoshka-1-3-gamaredons-gifts-that-keeps-unpacking-gammaphish-and-gammaworm/"
},
{
"evidence": [
"Sekoia (#3) states the operator runs dedicated IPs/domains that receive victim fingerprints via HTTP headers and serve VBScript payloads / config updates; HTTP 200 = execute VBScript, HTTP 404 = config update.",
"Sekoia mapped 55 new servers provisioned between 16 and 28 January 2026 with an average operational lifespan of ~24 hours, demonstrating high-frequency rotation. The single confirmed C2 IP and full network indicators are in the Sekoia Intelligence feed."
],
"id": "e012",
"observed_at": "2026-06-03T00:00:00Z",
"source": "Sekoia.io TDR: FSB's matryoshka (#1 GammaPhish/GammaWorm 2026-06-01, #2 GammaLoad 2026-06-03, #3 GammaSteel 2026-06-04)",
"type": "ip",
"value": "Operator-controlled C2 server (dedicated IP/domain; 55 hosts provisioned 16-28 Jan 2026, ~24h average lifespan)",
"x_reference_url": "https://blog.sekoia.io/fsbs-matryoshka-1-3-gamaredons-gifts-that-keeps-unpacking-gammaphish-and-gammaworm/"
},
{
"evidence": [
"Sekoia describes GammaWorm as the propagation component that resolves C2 via the dead-drop resolver chain, stores modules in NTFS ADS, and spreads via USB/network drives using malicious LNK shortcuts."
],
"id": "e013",
"observed_at": "2026-06-03T00:00:00Z",
"source": "Sekoia.io TDR: FSB's matryoshka (#1 GammaPhish/GammaWorm 2026-06-01, #2 GammaLoad 2026-06-03, #3 GammaSteel 2026-06-04)",
"type": "file",
"value": "GammaWorm (VBScript worm, formerly LitterDrifter/PteroLNK/PterodoUSB; >20,000 lines)",
"x_reference_url": "https://blog.sekoia.io/fsbs-matryoshka-1-3-gamaredons-gifts-that-keeps-unpacking-gammaphish-and-gammaworm/"
},
{
"evidence": [
"Sekoia (#3) describes GammaSteel as a modular PowerShell stealer staging 71 DPAPI-encrypted functions in the registry, hunting documents via drive scans, USB monitoring and active-edit surveillance."
],
"id": "e014",
"observed_at": "2026-06-03T00:00:00Z",
"source": "Sekoia.io TDR: FSB's matryoshka (#1 GammaPhish/GammaWorm 2026-06-01, #2 GammaLoad 2026-06-03, #3 GammaSteel 2026-06-04)",
"type": "file",
"value": "GammaLoad-deployed GammaSteel (fileless PowerShell stealer; 71 DPAPI-encrypted functions in HKCU\\Printers)",
"x_reference_url": "https://blog.sekoia.io/fsbs-matryoshka-3-3-gamaredons-gifts-that-keeps-unpacking-gammasteel/"
},
{
"evidence": [
"Sekoia (#3) states GammaSteel exfiltrates harvested documents to the legitimate S3-compatible service Tebi.io (and AWS S3), with fallback to hard-coded operator domains.",
"Trusted S3-compatible cloud storage abused as the exfiltration endpoint."
],
"id": "e015",
"observed_at": "2026-06-03T00:00:00Z",
"source": "Sekoia.io TDR: FSB's matryoshka (#1 GammaPhish/GammaWorm 2026-06-01, #2 GammaLoad 2026-06-03, #3 GammaSteel 2026-06-04)",
"type": "domain",
"value": "tebi.io (S3-compatible storage) / AWS S3 exfiltration endpoint",
"x_reference_url": "https://blog.sekoia.io/fsbs-matryoshka-3-3-gamaredons-gifts-that-keeps-unpacking-gammasteel/"
},
{
"evidence": [
"Sekoia (#3) states GammaSteel falls back to hard-coded operator-controlled domains when the S3-compatible exfiltration path is unavailable."
],
"id": "e016",
"observed_at": "2026-06-03T00:00:00Z",
"source": "Sekoia.io TDR: FSB's matryoshka (#1 GammaPhish/GammaWorm 2026-06-01, #2 GammaLoad 2026-06-03, #3 GammaSteel 2026-06-04)",
"type": "domain",
"value": "Hard-coded operator fallback domains (Russian-nexus) for exfiltration",
"x_reference_url": "https://blog.sekoia.io/fsbs-matryoshka-3-3-gamaredons-gifts-that-keeps-unpacking-gammasteel/"
}
],
"iim_version": "1.1",
"import_source": "manual-osint-report-to-iim-conversion",
"name": "Gamaredon (UAC-0010) 'Gamma' matryoshka: WinRAR CVE-2025-8088 to multi-platform dead-drop resolvers",
"needs_review": false,
"observed_at": "2026-06-03T00:00:00Z",
"relations": [
{
"confidence": "confirmed",
"from": "e001",
"sequence_order": 1,
"to": "e002",
"type": "drops",
"x_evidence": "The weaponized xHTML uses HTML smuggling to drop the malicious RAR archive."
},
{
"confidence": "confirmed",
"from": "e002",
"sequence_order": 2,
"to": "e003",
"type": "drops",
"x_evidence": "The RAR exploits CVE-2025-8088 to extract a hidden HTA into the Windows Startup directory."
},
{
"confidence": "confirmed",
"from": "e003",
"sequence_order": 3,
"to": "e004",
"type": "download",
"x_evidence": "The HTA runs mshta.exe against the operator URL (with www.bbc.com decoy path) to fetch GammaLoad."
},
{
"confidence": "confirmed",
"from": "e004",
"sequence_order": 4,
"to": "e005",
"type": "drops",
"x_evidence": "The mshta fetch retrieves the GammaLoad VBScript staging layer."
},
{
"confidence": "confirmed",
"from": "e005",
"sequence_order": 5,
"to": "e006",
"type": "references",
"x_evidence": "GammaLoad/GammaWorm resolve C2 by hopping through graph.org (Telegra.ph) as a dead-drop resolver."
},
{
"confidence": "confirmed",
"from": "e005",
"sequence_order": 6,
"to": "e007",
"type": "references",
"x_evidence": "Teletype.in is part of the dead-drop resolver resolution chain."
},
{
"confidence": "confirmed",
"from": "e005",
"sequence_order": 7,
"to": "e008",
"type": "references",
"x_evidence": "GammaWorm runs curl against a hard-coded public Telegram channel and parses the HTML for the obfuscated C2 IP."
},
{
"confidence": "confirmed",
"from": "e005",
"sequence_order": 8,
"to": "e009",
"type": "references",
"x_evidence": "Additional trusted-platform dead-drop resolvers (Write.as, Rentry.co, Mastodon) are used across the infrastructure."
},
{
"confidence": "confirmed",
"from": "e005",
"sequence_order": 9,
"to": "e010",
"type": "references",
"x_evidence": "The resolution chain also hops through a Cloudflare Workers subdomain."
},
{
"confidence": "likely",
"from": "e010",
"sequence_order": 10,
"to": "e011",
"type": "redirect",
"x_evidence": "DDR entries typically contain a Cloudflare quick-tunnel address fronting the operator origin."
},
{
"confidence": "confirmed",
"from": "e006",
"sequence_order": 11,
"to": "e012",
"type": "references",
"x_evidence": "The Telegra.ph/graph.org dead-drop resolves to the current operator-controlled C2 server, written to HKCU\\Console."
},
{
"confidence": "confirmed",
"from": "e008",
"sequence_order": 12,
"to": "e012",
"type": "references",
"x_evidence": "The Telegram dead drop publishes the active operator C2 IP that GammaWorm extracts."
},
{
"confidence": "likely",
"from": "e011",
"sequence_order": 13,
"to": "e012",
"type": "redirect",
"x_evidence": "The Cloudflare quick tunnel forwards to the operator-controlled origin server."
},
{
"confidence": "likely",
"from": "e005",
"sequence_order": 14,
"to": "e013",
"type": "drops",
"x_evidence": "GammaWorm is assessed to be dropped concurrently by GammaLoad (or introduced via weaponized USB)."
},
{
"confidence": "confirmed",
"from": "e005",
"sequence_order": 15,
"to": "e014",
"type": "drops",
"x_evidence": "The GammaLoad cascade ultimately stages and executes GammaSteel."
},
{
"confidence": "confirmed",
"from": "e013",
"sequence_order": 16,
"to": "e012",
"type": "connect",
"x_evidence": "GammaWorm posts the host fingerprint to the operator C2 via randomized HTTP headers; HTTP 200 = execute VBScript, HTTP 404 = config update."
},
{
"confidence": "confirmed",
"from": "e014",
"sequence_order": 17,
"to": "e015",
"type": "connect",
"x_evidence": "GammaSteel exfiltrates harvested documents to the S3-compatible service Tebi.io / AWS S3."
},
{
"confidence": "confirmed",
"from": "e014",
"sequence_order": 18,
"to": "e016",
"type": "connect",
"x_evidence": "GammaSteel falls back to hard-coded operator domains when the S3-compatible exfiltration path is unavailable."
}
],
"title": "Gamaredon (UAC-0010) 'Gamma' matryoshka: WinRAR CVE-2025-8088 to multi-platform dead-drop resolvers, Cloudflare and S3 exfiltration",
"x_iocs": {
"cve": [
"CVE-2025-8088"
],
"dead_drop_resolver_platforms": [
"graph.org",
"telegra.ph",
"teletype.in",
"public Telegram channels",
"write.as",
"rentry.co",
"mastodon (instances)",
"*.workers.dev (Cloudflare Workers)",
"*.trycloudflare.com (Cloudflare quick tunnels)",
"dynamic DNS services"
],
"exfiltration": [
"tebi.io (S3-compatible)",
"AWS S3",
"hard-coded operator fallback domains"
],
"infrastructure_note": [
"55 operator hosts provisioned 16-28 Jan 2026, ~24h average lifespan; single confirmed C2 IP and full network indicators in the Sekoia Intelligence feed"
],
"registry": [
"HKCU\\Console (GammaWorm/GammaLoad C2 cache)",
"HKCU\\Printers (GammaSteel 71 DPAPI modules)"
],
"sample_md5": [
"bf94f4056627907d86ce1cae8b44c67a (in-memory GammaLoad VBScript)"
]
},
"x_limitations": [
"Sekoia publishes a subset of hundreds of IOCs; the complete network indicators (the confirmed operator C2 IP, additional domains/URLs) are distributed via the Sekoia Intelligence feed rather than in full in the blog, so the operator C2 entity is modeled generically.",
"The dead-drop resolver platforms (e009) aggregate Write.as, Rentry.co and Mastodon into a single entity for readability; they can be split if per-URL granularity is needed.",
"Dynamic-DNS abuse (IIM-T008) on the operator fleet is inferred from the reporting and modeled with likely confidence.",
"Endpoint behavior (NTFS ADS module storage, DPAPI registry staging, USB/LNK propagation, scheduled-task persistence) is captured via ATT&CK/evidence rather than IIM techniques."
],
"x_publication_safety": "TLP:CLEAR-style OSINT chain derived only from public Sekoia.io reporting; granular network IOCs deliberately not reproduced beyond what Sekoia published openly.",
"x_report_published_at": "2026-06-01/2026-06-04 (three-part series)",
"x_resource_links_verified": true,
"x_selection_reason": "Exceptional IIM fit and unambiguous FSB attribution: archive-container delivery (WinRAR CVE-2025-8088), a layered dead-drop-resolver resolution chain across six+ trusted platforms, Cloudflare Workers/quick-tunnel ephemeral fronting, high-frequency disposable host rotation, and S3-compatible exfiltration. A near-complete tour of the IIM resolution/hosting/composition catalog and a strong reference for dead-drop-resolver modeling.",
"x_source": "Sekoia.io Threat Detection & Research (TDR)",
"x_source_title": "FSB's matryoshka - Gamaredon's gifts that keep unpacking (GammaPhish/GammaWorm, GammaLoad, GammaSteel)",
"x_source_url": "https://blog.sekoia.io/fsbs-matryoshka-1-3-gamaredons-gifts-that-keeps-unpacking-gammaphish-and-gammaworm/",
"x_source_urls": [
"https://blog.sekoia.io/fsbs-matryoshka-1-3-gamaredons-gifts-that-keeps-unpacking-gammaphish-and-gammaworm/",
"https://blog.sekoia.io/fsbs-matryoshka-2-3-gamaredons-gifts-that-keeps-unpacking-gammaload/",
"https://blog.sekoia.io/fsbs-matryoshka-3-3-gamaredons-gifts-that-keeps-unpacking-gammasteel/"
]
}