FSB Group Gamaredon Utilizes Windows Data Streams for Stealthy Worm Deployment in Ukraine
A Russian state-linked espionage group, Gamaredon, has been observed using a Windows file feature to hide a worm within Ukrainian networks. According to Sekoia, the worm is part of a campaign targeting Ukraine's government, military, and critical infrastructure. The worm, known as GammaWorm, employs NTFS Alternate Data Streams to conceal its modules, allowing it to operate without leaving traces on infected machines. The campaign began with a booby-trapped xHTML file that exploited a WinRAR flaw, CVE-2025-8088, to plant a hidden file in the Windows Startup folder. This file fetched further payloads from remote servers, maintaining stealth through scheduled tasks and registry changes. The worm propagates via USB sticks and network drives, using provocative Ukrainian-language filenames to lure users.