Gamaredon Builds Persistence Through Cloud and WinRAR Abuse

Gamaredon is keeping its foothold by stacking delivery paths, not by leaning on one lure or one domain. If defenders only block the phishing message, the campaign can come back through archive attachments, HTML smuggling, cloud dead-drops, and a patched WinRAR flaw that drops the downloader into Windows Startup so it runs again at next login. ESET says it saw 35 spear-phishing campaigns against Ukrainian government and military targets in 2025, most in the second half of the year. The group used archive attachments or XHTML files, HTA downloaders, new PowerShell tools, and CVE-2025-8088 to add persistence. It also leaned more on tunnel services, serverless workers, Telegra.ph, and GoFile to hide its back-end infrastructure. That mix makes takedowns and single-indicator blocking weaker than usual. The same campaign can keep reappearing under fresh infrastructure, with mainstream cloud and paste services doing the hiding for it.

Part of the PlainSec briefing for 2026-06-30

Sources