Skip to content
Gamaredon Exploits WinRAR to Deliver GammaWorm and GammaSteel Against Ukraine

Gamaredon Exploits WinRAR to Deliver GammaWorm and GammaSteel Against Ukraine

Thehackernews [email protected] (The Hacker News) June 2, 2026

The Russian hacking group known as Gamaredon has been attributed to the continued exploitation of a WinRAR vulnerability to deliver multiple malware families aimed at data theft and propagation.

Per Sekoia, the activity involves the weaponization of CVE-2025-8088, a path traversal flaw in WinRAR, to launch an HTML Application payload dubbed GammaPhish, which is then used to retrieve an

Extracted Entities

APT Groups (1)

Attack Types (1)

Campaigns (1)

Countries (1)

CVEs (1)

CWE Weaknesses (1)

Tools (1)