0x

guest@0xbase ~$ read-only mode. Posting requires EU location.

Gamaredon Espionage Group Uses NTFS Alternate Data Streams to Deliver Fileless Worm Targeting Ukraine (infosecurity-magazine.com)

· 57d ago · Report · Spotlight this ·
0xBASE INTEL BRIEF
  • Initial access via WinRAR path traversal CVE-2025-8088
  • Fileless worm stored in NTFS Alternate Data Streams
  • Persistence via scheduled tasks and registry modification
  • Propagation via USB and network drives with Ukrainian lure filenames
  • C2 via Telegram and Cloudflare dead drop resolvers
  • Full system wipe recommended for safe remediation

"Sekoia researchers report that FSB-linked group Gamaredon has deployed a fileless VBScript worm, GammaWorm, using NTFS Alternate Data Streams to hide its components on compromised systems targeting Ukrainian government and military networks. The infection chain begins with a malicious xHTML exploiting WinRAR flaw CVE-2025-8088 to plant an HTA file in the Windows Startup folder. GammaWorm then establishes persistence via scheduled tasks disguised as routine maintenance, propagates via USB and network drives using hidden shortcuts with Ukrainian-language lure filenames, and uses Telegram and Cloudflare as dead drop resolvers for C2 communication. Sekoia recommends full system wipe as the safest response to infection."

#NTFS alternate data streams #fileless VBScript worm #Gamaredon FSB group

Discussion Matrix

0 segments

no comments yet.