MEDIUMMalware
Global

Gamaredon Exploits WinRAR to Deliver GammaWorm and GammaSteel Against Ukraine

·Source: The Hacker News

Updated:

Executive Summary

The Russian hacking group known as Gamaredon has been attributed to the continued exploitation of a WinRAR vulnerability to deliver multiple malware families aimed at data theft and propagation. Per Sekoia, the activity involves the weaponization of CVE-2025-8088, a path traversal flaw in WinRAR, to launch an HTML Application payload dubbed GammaPhish, which is then used to retrieve an

Analysis

The Russian hacking group known as Gamaredon has been attributed to the continued exploitation of a WinRAR vulnerability to deliver multiple malware families aimed at data theft and propagation. Per Sekoia, the activity involves the weaponization of CVE-2025-8088, a path traversal flaw in WinRAR, to launch an HTML Application payload dubbed GammaPhish, which is then used to retrieve an

Indicators of Compromise (1)

CVE (1)
CVE-2025-8088
Source Attribution

Originally published by The Hacker News on Jun 2, 2026.

Related Threats