
Russian FSB-Linked Gamaredon Group Uses Fileless Worm in NTFS ADS for Ukrainian Espionage
CyberespionageMalwareHackingGeopoliticalThreatsRussiaUkraineFSBFilelessMalwareNTFSAPT
The Russian state-backed threat group Gamaredon, linked to the FSB, has been observed concealing a fileless worm within NTFS alternate data streams (ADS) to conduct espionage against Ukrainian targets. The malware leverages legitimate Windows features to evade detection, executing malicious payloads directly from data streams without writing files to disk. No specific CVE IDs, dates, or technical indicators such as hashes or command-and-control infrastructure were disclosed in the report. The attack primarily focuses on persistence and intelligence gathering within compromised systems. The campaign underscores the group’s continued targeting of Ukraine amid ongoing geopolitical tensions.