News

Gamaredon Uses WinRAR Vulnerability to Launch Modular Spy Campaign on Ukrainian Targets

  • Pierluigi Paganini--Securityaffairs.com
  • published date: 2026-06-04 10:53:09 UTC

Gamaredon exploits a WinRAR flaw to drop modular, nearly fileless malware on Ukrainian targets, hiding payloads in Windows streams and resolving C2s via Telegram. Sekoia’s Threat Detection & Research team dropped a YARA rule in late December 2025 to hunt for …

Gamaredon Uses WinRAR Vulnerability to Launch Modular Spy Campaign on Ukrainian Targets Sekoia’s Threat Detection & Research team dropped a YARA rule in late December 2025 to hunt for new initia… [+7935 chars]