Utopia Tech
Gamaredon Exploits WinRAR to Deliver GammaWorm and GammaSteel Against Ukraine
SecurityAI-assisted1 min read

Gamaredon Exploits WinRAR to Deliver GammaWorm and GammaSteel Against Ukraine

Russian threat actor Gamaredon is actively exploiting CVE-2025-8088, a path traversal vulnerability in WinRAR, to deploy multiple malware families including GammaPhish, GammaWorm, and GammaSteel targeting Ukrainian entities. The attack chain uses weaponized archives to deliver HTML Application payloads designed for data exfiltration and lateral propagation across compromised networks.

UT

Utopia Tech

June 2, 2026 · 1 min read

Share

The Russian hacking group known as Gamaredon has been attributed to the continued exploitation of a WinRAR vulnerability to deliver multiple malware families aimed at data theft and propagation. Per Sekoia, the activity involves the weaponization of CVE-2025-8088, a path traversal flaw in WinRAR, to launch an HTML Application payload dubbed GammaPhish, which is then used to retrieve an

Originally published at thehackernews.com

Share
▸ Want a deeper look?

Talk to an architect about applying this to your stack.

60-minute technical evaluation, no obligation. We'll map the ideas in this article to your environment.

Skip to main content