Russian Group Gamaredon Uses Windows Data Streams to Hide Cyber Espionage Worm
The Russian state-linked espionage group Gamaredon has been observed using a sophisticated worm that hides within Windows NTFS data streams to conduct cyber espionage in Ukraine. According to Sekoia, the worm is part of a campaign targeting Ukrainian government and military networks. The attack begins with a booby-trapped xHTML file that exploits a WinRAR vulnerability to plant a hidden file, which then downloads further payloads. The worm, known as GammaWorm, uses NTFS Alternate Data Streams to conceal its components, making it difficult to detect. It propagates through USB sticks and network drives, using deceptive filenames to lure users.