GamaWiper
- Malware type
- wiper
- Profile updated
- 2026-07-07 14:41:17
Targeted industries: government-and-public-sector
Targeted regions: country_code:ua
Context
According to ClearSky, this is a VBS-based wiper, deployed via exploitation of a vulnerable WinRAR version (CVE-2025-80880). They assess with medium confidence a link to Gamaredon.
Exploited vulnerabilities
- CVE-2025-80880 (vulnerability)
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Vbs.Gamawiper (report)
- x.com — 1995061537183011084 (report)