Threats · 77 days ago

Gamaredon Builds Persistence Through Cloud and WinRAR Abuse

Gamaredon is keeping its foothold by stacking delivery paths, not by leaning on one lure or one domain. If defenders only block the phishing message, the campaign can come back through archive attachments, HTML smuggling, cloud dead-drops, and a patched WinRAR flaw that drops the downloader into Windows Startup so it runs again at next login.

ESET says it saw 35 spear-phishing campaigns against Ukrainian government and military targets in 2025, most in the second half of the year. The group used archive attachments or XHTML files, HTA downloaders, new PowerShell tools, and CVE-2025-8088 to add persistence. It also leaned more on tunnel services, serverless workers, Telegra.ph, and GoFile to hide its back-end infrastructure.

That mix makes takedowns and single-indicator blocking weaker than usual. The same campaign can keep reappearing under fresh infrastructure, with mainstream cloud and paste services doing the hiding for it.

CVE-2025-8088

NVD KEV

Known exploited · CISA KEV

CVSS 8.8 HIGH: a path traversal vulnerability affecting the Windows version of WinRAR allows the attackers to execute arbitrary code by crafting malicious archive files. EPSS 95% (100th percentile).

CISA federal remediation date Sep 2 · date passed

Timeline

Sources

1 source covering this story

Entities

Part of the PlainSec briefing for 2026-06-30

Editions

Related stories