GammaLoad is a multi-stage script-based staging and loading component used by the Russia-linked Gamaredon threat actor, also tracked as Armageddon, Shuckworm, BlueAlpha, and UAC-0010, in long-running cyber-espionage operations primarily targeting Ukrainian government, military, and critical infrastructure organizations. It has been observed as an intermediate downloader and execution layer within Gamaredon’s broader modular "Gamma" ecosystem, alongside components such as GammaPhish for delivery, GammaWorm for propagation, and GammaSteel for data theft.
GammaLoad has been described in both VBScript and PowerShell forms across different campaigns and appears to function as a flexible loader rather than a final payload. Reported behavior includes host fingerprinting, collection of user and system information, retrieval of follow-on payloads from command-and-control infrastructure, execution of arbitrary script content, and support for persistence. In some operations it has updated registry-based network configuration through dead-drop resolver mechanisms and fetched additional VBScript payloads dynamically. It has also been associated with beaconing behavior and with enabling deployment of downstream implants including GammaSteel and, in some reporting, worm-like propagation components.
Observed intrusion chains commonly place GammaLoad after phishing or lure stages. Campaigns have used spearphishing emails, malicious Office documents with remote-template macros, weaponized archives, self-extracting archives, HTML smuggling, and HTA-based execution. More recent activity linked to Gamaredon used weaponized XHTML lures and exploitation of CVE-2025-8088 in WinRAR to launch an HTA stage that retrieved GammaLoad. Other reporting ties GammaLoad to staged VBScript cascades and to delivery chains involving GammaDrop, which writes GammaLoad to disk and helps establish persistence.
GammaLoad is associated with espionage-oriented post-compromise activity. High-confidence reporting links it to data exfiltration, credential theft, persistent access, and execution of additional malware. It has been used in campaigns that stole host information and documents and that maintained resilient access through modular, rapidly updated script components. Its role as a staging layer, combined with Gamaredon’s frequent use of legitimate services, cloud infrastructure, and dead-drop resolvers, makes it a durable and adaptable element of the group’s intrusion tradecraft.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
According to Sekoia, the attack consists of exploiting the bug CVE-2025-8088, a path traversal bug in WinRAR, to run an HTML App payload called GammaPhish, which is later used to get a VBScript payload from the C2 server.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Gamaredon’s infection chain: Spoofed emails, GammaDrop and GammaLoad ... Cyberattacks of the UAC-0010 group (Armageddon): malicious programs GammaLoad, GammaSteel ... UAC-0010 (Armageddon) cyberattacks using the GammaLoad.PS1_v2 malware
Since at least October 2023 BlueAlpha has delivered the custom VBScript malware GammaLoad, enabling data exfiltration, credential theft, and persistent access to compromised networks.
21 distinct techniques documented for this family, organized by ATT&CK tactic.
Grabs the IP address associated with the configured C2 domain using WMI WMI query format: SELECT * FROM Win32_PingStatus WHERE Address={configured_c2_domain}
resulting in the execution of arbitrary code retrieved from a command-and-control (C2) server
Following the downloading of the XML file onto victim networks, the attackers executed a PowerShell stealer.
The macro code inside the template is obfuscated by adding a lot of junk code. The VBScript code is obfuscated similar to the macro code.
Then the attackers used mshta.exe to download an XML file, which was likely masquerading as an HTML application file.
Sends a network request to download the next stage payload using the IP address obtained from step #2 and also exfiltrate the information collected from step #1 using the UserAgent field
Their primary objectives are to fingerprint the host system, update the network configuration in the registry using Dead Drop Resolvers (DDRs), fetch and execute arbitrary VBScript payloads from the C2 servers.
Their primary objectives are to fingerprint the host system, update the network configuration in the registry using Dead Drop Resolvers (DDRs), fetch and execute arbitrary VBScript payloads from the C2 servers.
Gamaredon’s infection chain: Spoofed emails, GammaDrop and GammaLoad
15 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Loader used by Gamaredon as part of operations focused on persistence, propagation, and document theft.
Intermediate staging layer composed of VBScript loaders that fingerprint the host, update network configuration in the registry using dead drop resolvers, and fetch and execute arbitrary VBScript payloads from C2 servers.
A loader in the infection chain that is likely deployed by GammaPhish and used to deliver other Gamaredon malware families such as GammaSteel, and possibly GammaWorm or GammaWipe.
An intermediate VBScript downloader in the Gamaredon infection chain that fingerprints the host, updates network configuration in the registry using dead drop resolvers, and fetches and executes arbitrary VBScript payloads from C2 servers.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.