Adversary Intelligence — 2026-05-18

Russian APT Gamaredon Deploys GammaDrop and GammaLoad in Ongoing Phishing Campaigns

BLUFGamaredon's sustained tooling development and named targeting of Ukrainian security installations make at least one new documented variant or campaign wave very likely before mid-August 2026, regardless of defensive responses.

Russian FSB-linked APT Gamaredon has conducted at least a dozen spearphishing waves against Ukrainian state institutions since September 2025, with the campaign still active GammaDrop and GammaLoad" data-source="HarfangLab" data-url="https://harfanglab.io/insidethelab/gamaredon-gammadrop-gammaload/" data-rt="primary">1. Emails are sent from compromised Ukrainian government accounts or spoofed headers, exploiting CVE-2025-8088 to silently write payloads to the victim's Startup folder 1. GammaDrop establishes initial foothold and delivers GammaLoad, which beacons victim profiling data to C2 servers enabling selective follow-on payload delivery; a GammaLoad variant updated April 27, 2026 shows continued active development 1. Supporting infrastructure layers Cloudflare Workers domains, fast-flux DNS, and dynamic DNS providers for command-and-control 1.

Analysis
The April 27 GammaLoad update and a May pivot to ARJ archives disguised as RAR and ZIP files confirm active evasion development. Gamaredon will very likely produce at least one new publicly documented variant or campaign wave by August 17, 2026, per a single HarfangLab report without CERT-UA or signals corroboration. The campaign's concentration on SSU installations across Luhansk, Lviv, and Chernivtsi oblasts points to named FSB collection requirements, though operator-gated payload delivery may instead reflect C2 longevity discipline rather than target-specific tasking. Ukrainian institutions' failure to enforce DMARC at reject-policy sustains the delivery mechanism regardless of tooling changes, and whether a confirmed new variant documents WinRAR mitigation bypasses will set CERT-UA's patch prioritization urgency.
3 sources
  1. Gamaredon's infection chain: Spoofed emails, GammaDrop and GammaLoad - HarfangLab
  2. Gamaredon Deploys GammaDrop, GammaLoad in Phishing Campaigns - GBHackers
  3. Gamaredon Launches New Phishing Campaign Against Government Entities Exploiting WinRAR Vulnerability - CyberPress

View in full brief →

UNCLASSIFIED // OPEN SOURCE