<img height="1" width="1" style="display: none" alt="" src="https://px.ads.linkedin.com/collect/?pid=1098858&amp;fmt=gif">

Russian FSB-Linked Worm Uses Hidden Windows Feature to Infiltrate Ukrainian Networks

FSB-linked GammaWorm targets Ukrainian systems using hard-to-detect methods; experts advise urgent WinRAR updates to thwart attacks.
Content Team

A Russian state-linked worm tied to the FSB's Gamaredon group is targeting Ukrainian government, military, and critical infrastructure — and it's remarkably hard to detect. Security firm Sekoia reconstructed an active infection chain first spotted in January 2026 that starts with a booby-trapped xHTML file, exploits a WinRAR path traversal flaw (CVE-2025-8088), and drops a hidden HTA file that runs on next login.

The worm, dubbed GammaWorm, hides its modules in NTFS Alternate Data Streams — a native Windows feature that leaves no visible trace in directory listings. It spreads via USB drives and network shares, pulls C2 addresses from Telegram and Cloudflare, and loops indefinitely as a backdoor. Sekoia recommends a full system wipe for infected machines and updating WinRAR to version 7.13 or later.

Source: Infosecurity Magazine

Share this article
Share on facebook Share on linkedin Share on twitter Share on email
blog_book_a_demo_cta_3x
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo