FSB’s matryoshka #2/3 – Gamaredon’s gifts that keeps unpacking – GammaLoad
June 4, 2026, 8:40 a.m.
Description
Gamaredon, an FSB-operated cyberespionage group, continues targeting Ukrainian government, military, and critical infrastructure through sophisticated multi-stage infection chains. This analysis examines GammaLoad, a collection of VBScript loaders that establish continuous access through three distinct stages. The malware leverages Dead Drop Resolvers on legitimate platforms including Telegram, Telegraph, and Check-Host to maintain persistent C2 communications while storing configurations in Windows registry keys. Each stage employs different techniques: the first fingerprints hosts and uses failover mechanisms, the second writes payloads to Alternate Data Streams and establishes persistence via scheduled tasks, and the third executes obfuscated PowerShell to deliver the final GammaSteel payload. This matryoshka architecture enables operators to deploy arbitrary payloads while remaining largely invisible by abusing trusted Windows features and cloud platforms.
Tags
Date
- Created: June 3, 2026, 1:18 p.m.
- Published: June 3, 2026, 1:18 p.m.
- Modified: June 4, 2026, 8:40 a.m.
Indicators
- https://insight-sweet-drainage-appreciated.trycloudflare.com/log
Additional Informations
- Defense
- Government
- insight-sweet-drainage-appreciated.trycloudflare.com
- Ukraine