GammaSteel is a modular information-stealing malware family used by the Russia-linked Gamaredon espionage group as the data-theft component of its broader Gamma malware ecosystem. It has been used in campaigns primarily targeting Ukrainian government, military, and critical infrastructure entities, and is associated with long-running cyberespionage activity attributed to Gamaredon, a cluster publicly linked to Russia’s FSB.
GammaSteel is delivered through earlier stages in the intrusion chain, most notably GammaLoad, after initial access obtained through spearphishing lures and malicious archive-based delivery chains. Reported campaigns have used weaponized document and archive lures, including Office-based phishing chains and later XHTML and WinRAR exploitation workflows, to establish execution and persistence before deploying GammaSteel.
The malware’s core function is theft of files likely to contain operationally valuable information. Observed variants recursively search local, removable, and remote storage for documents, archives, images, scripts, databases, and other selected file types, while avoiding common system directories. Some variants track previously stolen files to reduce duplicate exfiltration. GammaSteel has also been described as a modular PowerShell stealer that can stage numerous encrypted modules in the Windows registry, indicating a flexible architecture designed for rapid updates and compartmentalized functionality.
Exfiltration behavior includes transfer of collected files to cloud-backed storage and fallback operator-controlled servers. Public reporting specifically associates GammaSteel with exfiltration to S3-compatible storage as well as alternate attacker infrastructure when needed. In the broader Gamaredon ecosystem, supporting components can fingerprint hosts, retrieve arbitrary follow-on code, and maintain resilient access, enabling GammaSteel to operate as part of a persistent espionage platform rather than as a standalone commodity stealer.
GammaSteel fits Gamaredon’s longstanding emphasis on rapid development, heavy use of scripts and legitimate services, and sustained collection against Ukrainian targets. Its role within the Gamma ecosystem is focused on document theft and related intelligence collection in support of state-aligned espionage operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
According to Sekoia, the attack consists of exploiting the bug CVE-2025-8088, a path traversal bug in WinRAR, to run an HTML App payload called GammaPhish, which is later used to get a VBScript payload from the C2 server.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
A similar PowerShell script was described in CERT-UA's recent alert describing intrusions conducted by Gamaredon in the first half of 2022 using the GammaLoad and GammaSteel implants.
13 distinct techniques documented for this family, organized by ATT&CK tactic.
Kimsuky used malicious LNK files, the Dropbox API, GitHub Releases, and Google Drive for Information Theft and command execution.
GammaSteel manages three concurrent data acquisition mechanisms: recurring scans of local and network drives, hardware event monitoring for newly inserted USBs...
GammaSteel manages three concurrent data acquisition mechanisms: recurring scans of local and network drives...
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Document-stealing malware used by Gamaredon in campaigns emphasizing persistence and propagation.
Data theft component in Gamaredon’s modular malware taxonomy.
A modular information stealer that collects files with selected extensions and exfiltrates them to an AWS S3 bucket or attacker-controlled backup server.
A modular information stealer that collects files matching selected extensions and exfiltrates them to AWS S3 or an attacker-controlled server.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.