← feed

sekoia.2026.gamaredon-gammaworm-matryoshka-ddr-cloudflare-s3

Gamaredon (UAC-0010) 'Gamma' matryoshka: WinRAR CVE-2025-8088 to multi-platform dead-drop resolvers

IIM chain for Sekoia.io's three-part 'FSB's matryoshka' Gamaredon series (parts 1-3, 1-4 June 2026) reconstructing a January 2026 infection chain. A weaponized xHTML lure HTML-smuggles a malicious RAR that exploits CVE-2025-8088 to drop a hidden HTA (GammaPhish) into Startup. The HTA runs mshta against an operator URL (padded with a www.bbc.com decoy path) to fetch GammaLoad, an in-memory VBScript loader cascade that resolves and registry-caches its C2 through dead-drop resolvers on graph.org/Telegra.ph, Teletype.in, public Telegram channels, Write.as, Rentry.co, Mastodon and Cloudflare Workers, with Cloudflare quick tunnels fronting the operator origin. The operator runs a rapidly rotated fleet of dedicated hosts (55 servers in 12 days, ~24h average lifespan) that serve VBScript and signal via HTTP 200/404. GammaLoad deploys GammaWorm (propagation) and GammaSteel (fileless PowerShell stealer), which exfiltrates documents to the S3-compatible Tebi.io/AWS S3 with fallback to hard-coded operator domains.

confirmed IIM v1.1 MB-0001
Raw JSON
entities16
relations18
techniques9
published2026-06-18 11:31:44

Infrastructure map

Role-based chain map

click nodes or numbered relations to inspect the infrastructure path
entryredirectorstagingpayloadc2

Chain storyline

ordered IIM positions
1
entry

file

Weaponized xHTML lure (HTML smuggling), likely spear-phishing delivered

2
staging

file

Malicious RAR archive exploiting CVE-2025-8088 (WinRAR path traversal)

IIM-T024
3
staging

file

Hidden HTA dropped into the Windows Startup directory (GammaPhish)

4
staging

url

Operator mshta fetch URL with www.bbc.com decoy path -> retrieves GammaLoad

5
staging

file

GammaLoad VBScript loader cascade (4 in-memory stages; MD5 bf94f4056627907d86ce1cae8b44c67a observed)

IIM-T013
6
redirector

domain

graph.org (Telegra.ph / Teletype dead-drop resolver)

IIM-T013IIM-T006
7
redirector

domain

teletype.in (dead-drop resolver)

IIM-T013IIM-T006
8
redirector

url

Hard-coded public Telegram channel used as dead-drop resolver

IIM-T013IIM-T006IIM-T018
9
redirector

domain

write.as / rentry.co / mastodon (additional dead-drop resolver platforms)

IIM-T013IIM-T006
10
redirector

domain

Cloudflare Workers subdomain (*.workers.dev) used in the resolution chain

IIM-T005IIM-T006
11
redirector

url

Cloudflare quick tunnel (*.trycloudflare.com) concealing operator staging server

IIM-T005IIM-T002
12
c2

ip

Operator-controlled C2 server (dedicated IP/domain; 55 hosts provisioned 16-28 Jan 2026, ~24h average lifespan)

IIM-T010IIM-T011IIM-T008
13
payload

file

GammaWorm (VBScript worm, formerly LitterDrifter/PteroLNK/PterodoUSB; >20,000 lines)

14
payload

file

GammaLoad-deployed GammaSteel (fileless PowerShell stealer; 71 DPAPI-encrypted functions in HKCU\Printers)

15
c2

domain

tebi.io (S3-compatible storage) / AWS S3 exfiltration endpoint

IIM-T002IIM-T006
16
c2

domain

Hard-coded operator fallback domains (Russian-nexus) for exfiltration

IIM-T011

Relations

directed infrastructure edges
e001dropse002 confirmed
e002dropse003 confirmed
e003downloade004 confirmed
e004dropse005 confirmed
e005referencese006 confirmed
e005referencese007 confirmed
e005referencese008 confirmed
e005referencese009 confirmed
e005referencese010 confirmed
e010redirecte011 likely
e006referencese012 confirmed
e008referencese012 confirmed
e011redirecte012 likely
e005dropse013 likely
e005dropse014 confirmed
e013connecte012 confirmed
e014connecte015 confirmed
e014connecte016 confirmed

Entities & evidence

observable inventory
IDTypeValueSource / evidence
e001 file Weaponized xHTML lure (HTML smuggling), likely spear-phishing delivered
Sekoia (#1) identified a cluster of weaponized xHTML files that use HTML smuggling to drop a malicious RAR archive on the victim.
Assessed as the GammaPhish initial-access stage.
e002 file Malicious RAR archive exploiting CVE-2025-8088 (WinRAR path traversal)
Sekoia (#1) states the RAR exploits CVE-2025-8088 to extract a hidden HTA directly into the Windows Startup directory.
Archive container delivery abusing a WinRAR path-traversal flaw for Startup-folder placement.
e003 file Hidden HTA dropped into the Windows Startup directory (GammaPhish)
Sekoia (#1) states the RAR extracts a hidden HTA into Startup; the HTA runs mshta.exe with a URL whose path contains www.bbc.com to look legitimate in network logs.
e004 url Operator mshta fetch URL with www.bbc.com decoy path -> retrieves GammaLoad
Sekoia states the HTA runs mshta.exe against a URL embedding www.bbc.com in the path; that URL fetches the GammaLoad staging layer.
The www.bbc.com string is cosmetic path padding to blend with normal logs, not a redirect through the BBC.
e005 file GammaLoad VBScript loader cascade (4 in-memory stages; MD5 bf94f4056627907d86ce1cae8b44c67a observed)
Sekoia (#2) describes GammaLoad as a cascade of VBScript loaders executing loaders entirely in-memory, fingerprinting the host and updating C2 config in the registry (HKCU\Console) via dead-drop resolvers.
e006 domain graph.org (Telegra.ph / Teletype dead-drop resolver)
Sekoia states the C2 resolution chain hops through graph.org, Cloudflare Workers, Teletype, Telegra.ph and Telegram before reaching an operator server; each resolved URL is written to the registry.
Trusted publishing platform used as a dead-drop resolver hosting the current operational endpoint.
e007 domain teletype.in (dead-drop resolver)
Sekoia lists Teletype/Teletype.in among the dead-drop resolver platforms in the GammaWorm C2 resolution chain.
e008 url Hard-coded public Telegram channel used as dead-drop resolver
Sekoia states GammaWorm runs curl against a hard-coded public Telegram channel, parses the HTML for an obfuscated IP address, and posts the victim fingerprint back via randomized HTTP headers.
Public Telegram channel abused as a third-party dead drop that publishes the active C2 IP.
e009 domain write.as / rentry.co / mastodon (additional dead-drop resolver platforms)
Sekoia (#3) lists dead-drop resolvers hosted on public platforms including Telegram, Telegra.ph, Write.as, Rentry.co and Mastodon, alongside dynamic DNS services.
Modeled as one entity representing the additional trusted-platform DDRs observed across the infrastructure.
e010 domain Cloudflare Workers subdomain (*.workers.dev) used in the resolution chain
Sekoia states the resolution chain hops through Cloudflare Workers; Gamaredon also conceals staging servers behind Cloudflare quick tunnels.
Serverless edge worker used as an ephemeral resolution/staging node.
e011 url Cloudflare quick tunnel (*.trycloudflare.com) concealing operator staging server
Sekoia and prior HarfangLab analysis describe Gamaredon's Telegraph/Teletype DDRs typically containing a Cloudflare quick-tunnel address; quick tunnels require no registration and blend with legitimate traffic.
Ephemeral tunnel front concealing the operator-controlled origin.
e012 ip Operator-controlled C2 server (dedicated IP/domain; 55 hosts provisioned 16-28 Jan 2026, ~24h average lifespan)
Sekoia (#3) states the operator runs dedicated IPs/domains that receive victim fingerprints via HTTP headers and serve VBScript payloads / config updates; HTTP 200 = execute VBScript, HTTP 404 = config update.
Sekoia mapped 55 new servers provisioned between 16 and 28 January 2026 with an average operational lifespan of ~24 hours, demonstrating high-frequency rotation. The single confirmed C2 IP and full network indicators are in the Sekoia Intelligence feed.
e013 file GammaWorm (VBScript worm, formerly LitterDrifter/PteroLNK/PterodoUSB; >20,000 lines)
Sekoia describes GammaWorm as the propagation component that resolves C2 via the dead-drop resolver chain, stores modules in NTFS ADS, and spreads via USB/network drives using malicious LNK shortcuts.
e014 file GammaLoad-deployed GammaSteel (fileless PowerShell stealer; 71 DPAPI-encrypted functions in HKCU\Printers)
Sekoia (#3) describes GammaSteel as a modular PowerShell stealer staging 71 DPAPI-encrypted functions in the registry, hunting documents via drive scans, USB monitoring and active-edit surveillance.
e015 domain tebi.io (S3-compatible storage) / AWS S3 exfiltration endpoint
Sekoia (#3) states GammaSteel exfiltrates harvested documents to the legitimate S3-compatible service Tebi.io (and AWS S3), with fallback to hard-coded operator domains.
Trusted S3-compatible cloud storage abused as the exfiltration endpoint.
e016 domain Hard-coded operator fallback domains (Russian-nexus) for exfiltration
Sekoia (#3) states GammaSteel falls back to hard-coded operator-controlled domains when the S3-compatible exfiltration path is unavailable.

ATT&CK annotations

optional complementary mapping
T1566.001Spearphishing Attachment

T1027.006HTML Smuggling

T1203Exploitation for Client Execution (CVE-2025-8088 WinRAR)

T1547.001Registry Run Keys / Startup Folder

T1218.005Mshta

T1059.005Visual Basic

T1059.001PowerShell (GammaSteel)

T1564.004NTFS File Attributes (Alternate Data Streams)

T1053.005Scheduled Task

T1102.001Web Service: Dead Drop Resolver

T1071.001Application Layer Protocol: Web Protocols

T1091Replication Through Removable Media (USB)

T1567.002Exfiltration to Cloud Storage (S3-compatible)

Raw IIM JSON canonical body from MANTIS expand
{
  "actor_id": "Gamaredon",
  "attack_annotations": [
    {
      "name": "Spearphishing Attachment",
      "tactic": "Initial Access",
      "technique_id": "T1566.001"
    },
    {
      "name": "HTML Smuggling",
      "tactic": "Defense Evasion",
      "technique_id": "T1027.006"
    },
    {
      "name": "Exploitation for Client Execution (CVE-2025-8088 WinRAR)",
      "tactic": "Execution",
      "technique_id": "T1203"
    },
    {
      "name": "Registry Run Keys / Startup Folder",
      "tactic": "Persistence",
      "technique_id": "T1547.001"
    },
    {
      "name": "Mshta",
      "tactic": "Defense Evasion",
      "technique_id": "T1218.005"
    },
    {
      "name": "Visual Basic",
      "tactic": "Execution",
      "technique_id": "T1059.005"
    },
    {
      "name": "PowerShell (GammaSteel)",
      "tactic": "Execution",
      "technique_id": "T1059.001"
    },
    {
      "name": "NTFS File Attributes (Alternate Data Streams)",
      "tactic": "Defense Evasion",
      "technique_id": "T1564.004"
    },
    {
      "name": "Scheduled Task",
      "tactic": "Persistence",
      "technique_id": "T1053.005"
    },
    {
      "name": "Web Service: Dead Drop Resolver",
      "tactic": "Command and Control",
      "technique_id": "T1102.001"
    },
    {
      "name": "Application Layer Protocol: Web Protocols",
      "tactic": "Command and Control",
      "technique_id": "T1071.001"
    },
    {
      "name": "Replication Through Removable Media (USB)",
      "tactic": "Lateral Movement",
      "technique_id": "T1091"
    },
    {
      "name": "Exfiltration to Cloud Storage (S3-compatible)",
      "tactic": "Exfiltration",
      "technique_id": "T1567.002"
    }
  ],
  "chain": [
    {
      "entity_id": "e001",
      "review_notes": "HTML smuggling is endpoint defense-evasion (ATT&CK); modeled here only as the user-facing entry artifact.",
      "role": "entry",
      "role_confidence": "confirmed",
      "techniques": []
    },
    {
      "entity_id": "e002",
      "role": "staging",
      "role_confidence": "confirmed",
      "technique_confidence": "confirmed",
      "techniques": [
        "IIM-T024"
      ]
    },
    {
      "entity_id": "e003",
      "role": "staging",
      "role_confidence": "confirmed",
      "techniques": []
    },
    {
      "entity_id": "e004",
      "review_notes": "www.bbc.com path string is cosmetic log-blending, not a routing technique.",
      "role": "staging",
      "role_confidence": "confirmed",
      "techniques": []
    },
    {
      "entity_id": "e005",
      "review_notes": "GammaLoad updates its registry-cached C2 config via dead-drop resolvers before fetching further VBScript.",
      "role": "staging",
      "role_confidence": "confirmed",
      "technique_confidence": "confirmed",
      "techniques": [
        "IIM-T013"
      ]
    },
    {
      "entity_id": "e006",
      "role": "redirector",
      "role_confidence": "confirmed",
      "technique_confidence": "confirmed",
      "techniques": [
        "IIM-T013",
        "IIM-T006"
      ]
    },
    {
      "entity_id": "e007",
      "role": "redirector",
      "role_confidence": "confirmed",
      "technique_confidence": "confirmed",
      "techniques": [
        "IIM-T013",
        "IIM-T006"
      ]
    },
    {
      "entity_id": "e008",
      "role": "redirector",
      "role_confidence": "confirmed",
      "technique_confidence": "confirmed",
      "techniques": [
        "IIM-T013",
        "IIM-T006",
        "IIM-T018"
      ]
    },
    {
      "entity_id": "e009",
      "review_notes": "Single entity aggregating additional trusted-platform DDRs (Write.as, Rentry.co, Mastodon).",
      "role": "redirector",
      "role_confidence": "confirmed",
      "technique_confidence": "confirmed",
      "techniques": [
        "IIM-T013",
        "IIM-T006"
      ]
    },
    {
      "entity_id": "e010",
      "role": "redirector",
      "role_confidence": "confirmed",
      "technique_confidence": "confirmed",
      "techniques": [
        "IIM-T005",
        "IIM-T006"
      ]
    },
    {
      "entity_id": "e011",
      "review_notes": "Cloudflare quick tunnel as ephemeral front; T002 cloud-hosting tagging is the underlying Cloudflare substrate.",
      "role": "redirector",
      "role_confidence": "confirmed",
      "technique_confidence": "likely",
      "techniques": [
        "IIM-T005",
        "IIM-T002"
      ]
    },
    {
      "entity_id": "e012",
      "review_notes": "Disposable, rapidly rotated operator hosts (~24h lifespan, 55 in 12 days); dynamic-DNS (T008) inferred from the DDR/dynamic-DNS reporting and modeled as likely.",
      "role": "c2",
      "role_confidence": "confirmed",
      "technique_confidence": "likely",
      "techniques": [
        "IIM-T010",
        "IIM-T011",
        "IIM-T008"
      ]
    },
    {
      "entity_id": "e013",
      "role": "payload",
      "role_confidence": "confirmed",
      "techniques": []
    },
    {
      "entity_id": "e014",
      "role": "payload",
      "role_confidence": "confirmed",
      "techniques": []
    },
    {
      "entity_id": "e015",
      "review_notes": "S3-compatible exfiltration endpoint (trusted cloud storage) acting as the data-out C2 sink.",
      "role": "c2",
      "role_confidence": "confirmed",
      "technique_confidence": "confirmed",
      "techniques": [
        "IIM-T002",
        "IIM-T006"
      ]
    },
    {
      "entity_id": "e016",
      "review_notes": "Operator fallback exfiltration domains; rotation inferred from the broader high-frequency host-rotation pattern.",
      "role": "c2",
      "role_confidence": "confirmed",
      "technique_confidence": "likely",
      "techniques": [
        "IIM-T011"
      ]
    }
  ],
  "chain_id": "sekoia.2026.gamaredon-gammaworm-matryoshka-ddr-cloudflare-s3",
  "confidence": "confirmed",
  "description": "IIM chain for Sekoia.io's three-part 'FSB's matryoshka' Gamaredon series (parts 1-3, 1-4 June 2026) reconstructing a January 2026 infection chain. A weaponized xHTML lure HTML-smuggles a malicious RAR that exploits CVE-2025-8088 to drop a hidden HTA (GammaPhish) into Startup. The HTA runs mshta against an operator URL (padded with a www.bbc.com decoy path) to fetch GammaLoad, an in-memory VBScript loader cascade that resolves and registry-caches its C2 through dead-drop resolvers on graph.org/Telegra.ph, Teletype.in, public Telegram channels, Write.as, Rentry.co, Mastodon and Cloudflare Workers, with Cloudflare quick tunnels fronting the operator origin. The operator runs a rapidly rotated fleet of dedicated hosts (55 servers in 12 days, ~24h average lifespan) that serve VBScript and signal via HTTP 200/404. GammaLoad deploys GammaWorm (propagation) and GammaSteel (fileless PowerShell stealer), which exfiltrates documents to the S3-compatible Tebi.io/AWS S3 with fallback to hard-coded operator domains.",
  "entities": [
    {
      "evidence": [
        "Sekoia (#1) identified a cluster of weaponized xHTML files that use HTML smuggling to drop a malicious RAR archive on the victim.",
        "Assessed as the GammaPhish initial-access stage."
      ],
      "id": "e001",
      "observed_at": "2026-06-03T00:00:00Z",
      "source": "Sekoia.io TDR: FSB's matryoshka (#1 GammaPhish/GammaWorm 2026-06-01, #2 GammaLoad 2026-06-03, #3 GammaSteel 2026-06-04)",
      "type": "file",
      "value": "Weaponized xHTML lure (HTML smuggling), likely spear-phishing delivered",
      "x_reference_url": "https://blog.sekoia.io/fsbs-matryoshka-1-3-gamaredons-gifts-that-keeps-unpacking-gammaphish-and-gammaworm/"
    },
    {
      "evidence": [
        "Sekoia (#1) states the RAR exploits CVE-2025-8088 to extract a hidden HTA directly into the Windows Startup directory.",
        "Archive container delivery abusing a WinRAR path-traversal flaw for Startup-folder placement."
      ],
      "id": "e002",
      "observed_at": "2026-06-03T00:00:00Z",
      "source": "Sekoia.io TDR: FSB's matryoshka (#1 GammaPhish/GammaWorm 2026-06-01, #2 GammaLoad 2026-06-03, #3 GammaSteel 2026-06-04)",
      "type": "file",
      "value": "Malicious RAR archive exploiting CVE-2025-8088 (WinRAR path traversal)",
      "x_reference_url": "https://blog.sekoia.io/fsbs-matryoshka-1-3-gamaredons-gifts-that-keeps-unpacking-gammaphish-and-gammaworm/"
    },
    {
      "evidence": [
        "Sekoia (#1) states the RAR extracts a hidden HTA into Startup; the HTA runs mshta.exe with a URL whose path contains www.bbc.com to look legitimate in network logs."
      ],
      "id": "e003",
      "observed_at": "2026-06-03T00:00:00Z",
      "source": "Sekoia.io TDR: FSB's matryoshka (#1 GammaPhish/GammaWorm 2026-06-01, #2 GammaLoad 2026-06-03, #3 GammaSteel 2026-06-04)",
      "type": "file",
      "value": "Hidden HTA dropped into the Windows Startup directory (GammaPhish)",
      "x_reference_url": "https://blog.sekoia.io/fsbs-matryoshka-1-3-gamaredons-gifts-that-keeps-unpacking-gammaphish-and-gammaworm/"
    },
    {
      "evidence": [
        "Sekoia states the HTA runs mshta.exe against a URL embedding www.bbc.com in the path; that URL fetches the GammaLoad staging layer.",
        "The www.bbc.com string is cosmetic path padding to blend with normal logs, not a redirect through the BBC."
      ],
      "id": "e004",
      "observed_at": "2026-06-03T00:00:00Z",
      "source": "Sekoia.io TDR: FSB's matryoshka (#1 GammaPhish/GammaWorm 2026-06-01, #2 GammaLoad 2026-06-03, #3 GammaSteel 2026-06-04)",
      "type": "url",
      "value": "Operator mshta fetch URL with www.bbc.com decoy path -> retrieves GammaLoad",
      "x_reference_url": "https://blog.sekoia.io/fsbs-matryoshka-1-3-gamaredons-gifts-that-keeps-unpacking-gammaphish-and-gammaworm/"
    },
    {
      "evidence": [
        "Sekoia (#2) describes GammaLoad as a cascade of VBScript loaders executing loaders entirely in-memory, fingerprinting the host and updating C2 config in the registry (HKCU\\Console) via dead-drop resolvers."
      ],
      "id": "e005",
      "observed_at": "2026-06-03T00:00:00Z",
      "source": "Sekoia.io TDR: FSB's matryoshka (#1 GammaPhish/GammaWorm 2026-06-01, #2 GammaLoad 2026-06-03, #3 GammaSteel 2026-06-04)",
      "type": "file",
      "value": "GammaLoad VBScript loader cascade (4 in-memory stages; MD5 bf94f4056627907d86ce1cae8b44c67a observed)",
      "x_reference_url": "https://blog.sekoia.io/fsbs-matryoshka-2-3-gamaredons-gifts-that-keeps-unpacking-gammaload/"
    },
    {
      "evidence": [
        "Sekoia states the C2 resolution chain hops through graph.org, Cloudflare Workers, Teletype, Telegra.ph and Telegram before reaching an operator server; each resolved URL is written to the registry.",
        "Trusted publishing platform used as a dead-drop resolver hosting the current operational endpoint."
      ],
      "id": "e006",
      "observed_at": "2026-06-03T00:00:00Z",
      "source": "Sekoia.io TDR: FSB's matryoshka (#1 GammaPhish/GammaWorm 2026-06-01, #2 GammaLoad 2026-06-03, #3 GammaSteel 2026-06-04)",
      "type": "domain",
      "value": "graph.org (Telegra.ph / Teletype dead-drop resolver)",
      "x_reference_url": "https://blog.sekoia.io/fsbs-matryoshka-1-3-gamaredons-gifts-that-keeps-unpacking-gammaphish-and-gammaworm/"
    },
    {
      "evidence": [
        "Sekoia lists Teletype/Teletype.in among the dead-drop resolver platforms in the GammaWorm C2 resolution chain."
      ],
      "id": "e007",
      "observed_at": "2026-06-03T00:00:00Z",
      "source": "Sekoia.io TDR: FSB's matryoshka (#1 GammaPhish/GammaWorm 2026-06-01, #2 GammaLoad 2026-06-03, #3 GammaSteel 2026-06-04)",
      "type": "domain",
      "value": "teletype.in (dead-drop resolver)",
      "x_reference_url": "https://blog.sekoia.io/fsbs-matryoshka-1-3-gamaredons-gifts-that-keeps-unpacking-gammaphish-and-gammaworm/"
    },
    {
      "evidence": [
        "Sekoia states GammaWorm runs curl against a hard-coded public Telegram channel, parses the HTML for an obfuscated IP address, and posts the victim fingerprint back via randomized HTTP headers.",
        "Public Telegram channel abused as a third-party dead drop that publishes the active C2 IP."
      ],
      "id": "e008",
      "observed_at": "2026-06-03T00:00:00Z",
      "source": "Sekoia.io TDR: FSB's matryoshka (#1 GammaPhish/GammaWorm 2026-06-01, #2 GammaLoad 2026-06-03, #3 GammaSteel 2026-06-04)",
      "type": "url",
      "value": "Hard-coded public Telegram channel used as dead-drop resolver",
      "x_reference_url": "https://blog.sekoia.io/fsbs-matryoshka-1-3-gamaredons-gifts-that-keeps-unpacking-gammaphish-and-gammaworm/"
    },
    {
      "evidence": [
        "Sekoia (#3) lists dead-drop resolvers hosted on public platforms including Telegram, Telegra.ph, Write.as, Rentry.co and Mastodon, alongside dynamic DNS services.",
        "Modeled as one entity representing the additional trusted-platform DDRs observed across the infrastructure."
      ],
      "id": "e009",
      "observed_at": "2026-06-03T00:00:00Z",
      "source": "Sekoia.io TDR: FSB's matryoshka (#1 GammaPhish/GammaWorm 2026-06-01, #2 GammaLoad 2026-06-03, #3 GammaSteel 2026-06-04)",
      "type": "domain",
      "value": "write.as / rentry.co / mastodon (additional dead-drop resolver platforms)",
      "x_reference_url": "https://blog.sekoia.io/fsbs-matryoshka-3-3-gamaredons-gifts-that-keeps-unpacking-gammasteel/"
    },
    {
      "evidence": [
        "Sekoia states the resolution chain hops through Cloudflare Workers; Gamaredon also conceals staging servers behind Cloudflare quick tunnels.",
        "Serverless edge worker used as an ephemeral resolution/staging node."
      ],
      "id": "e010",
      "observed_at": "2026-06-03T00:00:00Z",
      "source": "Sekoia.io TDR: FSB's matryoshka (#1 GammaPhish/GammaWorm 2026-06-01, #2 GammaLoad 2026-06-03, #3 GammaSteel 2026-06-04)",
      "type": "domain",
      "value": "Cloudflare Workers subdomain (*.workers.dev) used in the resolution chain",
      "x_reference_url": "https://blog.sekoia.io/fsbs-matryoshka-1-3-gamaredons-gifts-that-keeps-unpacking-gammaphish-and-gammaworm/"
    },
    {
      "evidence": [
        "Sekoia and prior HarfangLab analysis describe Gamaredon's Telegraph/Teletype DDRs typically containing a Cloudflare quick-tunnel address; quick tunnels require no registration and blend with legitimate traffic.",
        "Ephemeral tunnel front concealing the operator-controlled origin."
      ],
      "id": "e011",
      "observed_at": "2026-06-03T00:00:00Z",
      "source": "Sekoia.io TDR: FSB's matryoshka (#1 GammaPhish/GammaWorm 2026-06-01, #2 GammaLoad 2026-06-03, #3 GammaSteel 2026-06-04)",
      "type": "url",
      "value": "Cloudflare quick tunnel (*.trycloudflare.com) concealing operator staging server",
      "x_reference_url": "https://blog.sekoia.io/fsbs-matryoshka-1-3-gamaredons-gifts-that-keeps-unpacking-gammaphish-and-gammaworm/"
    },
    {
      "evidence": [
        "Sekoia (#3) states the operator runs dedicated IPs/domains that receive victim fingerprints via HTTP headers and serve VBScript payloads / config updates; HTTP 200 = execute VBScript, HTTP 404 = config update.",
        "Sekoia mapped 55 new servers provisioned between 16 and 28 January 2026 with an average operational lifespan of ~24 hours, demonstrating high-frequency rotation. The single confirmed C2 IP and full network indicators are in the Sekoia Intelligence feed."
      ],
      "id": "e012",
      "observed_at": "2026-06-03T00:00:00Z",
      "source": "Sekoia.io TDR: FSB's matryoshka (#1 GammaPhish/GammaWorm 2026-06-01, #2 GammaLoad 2026-06-03, #3 GammaSteel 2026-06-04)",
      "type": "ip",
      "value": "Operator-controlled C2 server (dedicated IP/domain; 55 hosts provisioned 16-28 Jan 2026, ~24h average lifespan)",
      "x_reference_url": "https://blog.sekoia.io/fsbs-matryoshka-1-3-gamaredons-gifts-that-keeps-unpacking-gammaphish-and-gammaworm/"
    },
    {
      "evidence": [
        "Sekoia describes GammaWorm as the propagation component that resolves C2 via the dead-drop resolver chain, stores modules in NTFS ADS, and spreads via USB/network drives using malicious LNK shortcuts."
      ],
      "id": "e013",
      "observed_at": "2026-06-03T00:00:00Z",
      "source": "Sekoia.io TDR: FSB's matryoshka (#1 GammaPhish/GammaWorm 2026-06-01, #2 GammaLoad 2026-06-03, #3 GammaSteel 2026-06-04)",
      "type": "file",
      "value": "GammaWorm (VBScript worm, formerly LitterDrifter/PteroLNK/PterodoUSB; >20,000 lines)",
      "x_reference_url": "https://blog.sekoia.io/fsbs-matryoshka-1-3-gamaredons-gifts-that-keeps-unpacking-gammaphish-and-gammaworm/"
    },
    {
      "evidence": [
        "Sekoia (#3) describes GammaSteel as a modular PowerShell stealer staging 71 DPAPI-encrypted functions in the registry, hunting documents via drive scans, USB monitoring and active-edit surveillance."
      ],
      "id": "e014",
      "observed_at": "2026-06-03T00:00:00Z",
      "source": "Sekoia.io TDR: FSB's matryoshka (#1 GammaPhish/GammaWorm 2026-06-01, #2 GammaLoad 2026-06-03, #3 GammaSteel 2026-06-04)",
      "type": "file",
      "value": "GammaLoad-deployed GammaSteel (fileless PowerShell stealer; 71 DPAPI-encrypted functions in HKCU\\Printers)",
      "x_reference_url": "https://blog.sekoia.io/fsbs-matryoshka-3-3-gamaredons-gifts-that-keeps-unpacking-gammasteel/"
    },
    {
      "evidence": [
        "Sekoia (#3) states GammaSteel exfiltrates harvested documents to the legitimate S3-compatible service Tebi.io (and AWS S3), with fallback to hard-coded operator domains.",
        "Trusted S3-compatible cloud storage abused as the exfiltration endpoint."
      ],
      "id": "e015",
      "observed_at": "2026-06-03T00:00:00Z",
      "source": "Sekoia.io TDR: FSB's matryoshka (#1 GammaPhish/GammaWorm 2026-06-01, #2 GammaLoad 2026-06-03, #3 GammaSteel 2026-06-04)",
      "type": "domain",
      "value": "tebi.io (S3-compatible storage) / AWS S3 exfiltration endpoint",
      "x_reference_url": "https://blog.sekoia.io/fsbs-matryoshka-3-3-gamaredons-gifts-that-keeps-unpacking-gammasteel/"
    },
    {
      "evidence": [
        "Sekoia (#3) states GammaSteel falls back to hard-coded operator-controlled domains when the S3-compatible exfiltration path is unavailable."
      ],
      "id": "e016",
      "observed_at": "2026-06-03T00:00:00Z",
      "source": "Sekoia.io TDR: FSB's matryoshka (#1 GammaPhish/GammaWorm 2026-06-01, #2 GammaLoad 2026-06-03, #3 GammaSteel 2026-06-04)",
      "type": "domain",
      "value": "Hard-coded operator fallback domains (Russian-nexus) for exfiltration",
      "x_reference_url": "https://blog.sekoia.io/fsbs-matryoshka-3-3-gamaredons-gifts-that-keeps-unpacking-gammasteel/"
    }
  ],
  "iim_version": "1.1",
  "import_source": "manual-osint-report-to-iim-conversion",
  "name": "Gamaredon (UAC-0010) 'Gamma' matryoshka: WinRAR CVE-2025-8088 to multi-platform dead-drop resolvers",
  "needs_review": false,
  "observed_at": "2026-06-03T00:00:00Z",
  "relations": [
    {
      "confidence": "confirmed",
      "from": "e001",
      "sequence_order": 1,
      "to": "e002",
      "type": "drops",
      "x_evidence": "The weaponized xHTML uses HTML smuggling to drop the malicious RAR archive."
    },
    {
      "confidence": "confirmed",
      "from": "e002",
      "sequence_order": 2,
      "to": "e003",
      "type": "drops",
      "x_evidence": "The RAR exploits CVE-2025-8088 to extract a hidden HTA into the Windows Startup directory."
    },
    {
      "confidence": "confirmed",
      "from": "e003",
      "sequence_order": 3,
      "to": "e004",
      "type": "download",
      "x_evidence": "The HTA runs mshta.exe against the operator URL (with www.bbc.com decoy path) to fetch GammaLoad."
    },
    {
      "confidence": "confirmed",
      "from": "e004",
      "sequence_order": 4,
      "to": "e005",
      "type": "drops",
      "x_evidence": "The mshta fetch retrieves the GammaLoad VBScript staging layer."
    },
    {
      "confidence": "confirmed",
      "from": "e005",
      "sequence_order": 5,
      "to": "e006",
      "type": "references",
      "x_evidence": "GammaLoad/GammaWorm resolve C2 by hopping through graph.org (Telegra.ph) as a dead-drop resolver."
    },
    {
      "confidence": "confirmed",
      "from": "e005",
      "sequence_order": 6,
      "to": "e007",
      "type": "references",
      "x_evidence": "Teletype.in is part of the dead-drop resolver resolution chain."
    },
    {
      "confidence": "confirmed",
      "from": "e005",
      "sequence_order": 7,
      "to": "e008",
      "type": "references",
      "x_evidence": "GammaWorm runs curl against a hard-coded public Telegram channel and parses the HTML for the obfuscated C2 IP."
    },
    {
      "confidence": "confirmed",
      "from": "e005",
      "sequence_order": 8,
      "to": "e009",
      "type": "references",
      "x_evidence": "Additional trusted-platform dead-drop resolvers (Write.as, Rentry.co, Mastodon) are used across the infrastructure."
    },
    {
      "confidence": "confirmed",
      "from": "e005",
      "sequence_order": 9,
      "to": "e010",
      "type": "references",
      "x_evidence": "The resolution chain also hops through a Cloudflare Workers subdomain."
    },
    {
      "confidence": "likely",
      "from": "e010",
      "sequence_order": 10,
      "to": "e011",
      "type": "redirect",
      "x_evidence": "DDR entries typically contain a Cloudflare quick-tunnel address fronting the operator origin."
    },
    {
      "confidence": "confirmed",
      "from": "e006",
      "sequence_order": 11,
      "to": "e012",
      "type": "references",
      "x_evidence": "The Telegra.ph/graph.org dead-drop resolves to the current operator-controlled C2 server, written to HKCU\\Console."
    },
    {
      "confidence": "confirmed",
      "from": "e008",
      "sequence_order": 12,
      "to": "e012",
      "type": "references",
      "x_evidence": "The Telegram dead drop publishes the active operator C2 IP that GammaWorm extracts."
    },
    {
      "confidence": "likely",
      "from": "e011",
      "sequence_order": 13,
      "to": "e012",
      "type": "redirect",
      "x_evidence": "The Cloudflare quick tunnel forwards to the operator-controlled origin server."
    },
    {
      "confidence": "likely",
      "from": "e005",
      "sequence_order": 14,
      "to": "e013",
      "type": "drops",
      "x_evidence": "GammaWorm is assessed to be dropped concurrently by GammaLoad (or introduced via weaponized USB)."
    },
    {
      "confidence": "confirmed",
      "from": "e005",
      "sequence_order": 15,
      "to": "e014",
      "type": "drops",
      "x_evidence": "The GammaLoad cascade ultimately stages and executes GammaSteel."
    },
    {
      "confidence": "confirmed",
      "from": "e013",
      "sequence_order": 16,
      "to": "e012",
      "type": "connect",
      "x_evidence": "GammaWorm posts the host fingerprint to the operator C2 via randomized HTTP headers; HTTP 200 = execute VBScript, HTTP 404 = config update."
    },
    {
      "confidence": "confirmed",
      "from": "e014",
      "sequence_order": 17,
      "to": "e015",
      "type": "connect",
      "x_evidence": "GammaSteel exfiltrates harvested documents to the S3-compatible service Tebi.io / AWS S3."
    },
    {
      "confidence": "confirmed",
      "from": "e014",
      "sequence_order": 18,
      "to": "e016",
      "type": "connect",
      "x_evidence": "GammaSteel falls back to hard-coded operator domains when the S3-compatible exfiltration path is unavailable."
    }
  ],
  "title": "Gamaredon (UAC-0010) 'Gamma' matryoshka: WinRAR CVE-2025-8088 to multi-platform dead-drop resolvers, Cloudflare and S3 exfiltration",
  "x_iocs": {
    "cve": [
      "CVE-2025-8088"
    ],
    "dead_drop_resolver_platforms": [
      "graph.org",
      "telegra.ph",
      "teletype.in",
      "public Telegram channels",
      "write.as",
      "rentry.co",
      "mastodon (instances)",
      "*.workers.dev (Cloudflare Workers)",
      "*.trycloudflare.com (Cloudflare quick tunnels)",
      "dynamic DNS services"
    ],
    "exfiltration": [
      "tebi.io (S3-compatible)",
      "AWS S3",
      "hard-coded operator fallback domains"
    ],
    "infrastructure_note": [
      "55 operator hosts provisioned 16-28 Jan 2026, ~24h average lifespan; single confirmed C2 IP and full network indicators in the Sekoia Intelligence feed"
    ],
    "registry": [
      "HKCU\\Console (GammaWorm/GammaLoad C2 cache)",
      "HKCU\\Printers (GammaSteel 71 DPAPI modules)"
    ],
    "sample_md5": [
      "bf94f4056627907d86ce1cae8b44c67a (in-memory GammaLoad VBScript)"
    ]
  },
  "x_limitations": [
    "Sekoia publishes a subset of hundreds of IOCs; the complete network indicators (the confirmed operator C2 IP, additional domains/URLs) are distributed via the Sekoia Intelligence feed rather than in full in the blog, so the operator C2 entity is modeled generically.",
    "The dead-drop resolver platforms (e009) aggregate Write.as, Rentry.co and Mastodon into a single entity for readability; they can be split if per-URL granularity is needed.",
    "Dynamic-DNS abuse (IIM-T008) on the operator fleet is inferred from the reporting and modeled with likely confidence.",
    "Endpoint behavior (NTFS ADS module storage, DPAPI registry staging, USB/LNK propagation, scheduled-task persistence) is captured via ATT&CK/evidence rather than IIM techniques."
  ],
  "x_publication_safety": "TLP:CLEAR-style OSINT chain derived only from public Sekoia.io reporting; granular network IOCs deliberately not reproduced beyond what Sekoia published openly.",
  "x_report_published_at": "2026-06-01/2026-06-04 (three-part series)",
  "x_resource_links_verified": true,
  "x_selection_reason": "Exceptional IIM fit and unambiguous FSB attribution: archive-container delivery (WinRAR CVE-2025-8088), a layered dead-drop-resolver resolution chain across six+ trusted platforms, Cloudflare Workers/quick-tunnel ephemeral fronting, high-frequency disposable host rotation, and S3-compatible exfiltration. A near-complete tour of the IIM resolution/hosting/composition catalog and a strong reference for dead-drop-resolver modeling.",
  "x_source": "Sekoia.io Threat Detection & Research (TDR)",
  "x_source_title": "FSB's matryoshka - Gamaredon's gifts that keep unpacking (GammaPhish/GammaWorm, GammaLoad, GammaSteel)",
  "x_source_url": "https://blog.sekoia.io/fsbs-matryoshka-1-3-gamaredons-gifts-that-keeps-unpacking-gammaphish-and-gammaworm/",
  "x_source_urls": [
    "https://blog.sekoia.io/fsbs-matryoshka-1-3-gamaredons-gifts-that-keeps-unpacking-gammaphish-and-gammaworm/",
    "https://blog.sekoia.io/fsbs-matryoshka-2-3-gamaredons-gifts-that-keeps-unpacking-gammaload/",
    "https://blog.sekoia.io/fsbs-matryoshka-3-3-gamaredons-gifts-that-keeps-unpacking-gammasteel/"
  ]
}