Currently, this bot follows AlienVault, CryptoCTI, and Cyber74Team on OTX AlienVault. If you have more suggestions, please send a note to @mike. Update 2025/09/15: At the suggestion of an anonymous researcher, I've added the following accounts: -cyberhunter_nl -tr2222200 -tr1sa111 -bluenumberone -dekarituraj -feisty-swim1410 If they become overwhelming or repetitive I will gladly accept suggestions to remove any. A little bot maintained by @mike to post the latest pulses from Open Threat Exchange. Profile picture is Beezlebot, the Robot Devil, from Futurama. Header picture is a holograph-stylized image with the word "Malware" highlighted. Unaffiliated with OTX or AlienVault WARNING: This is crowdsourced data posted by a bot and is not guaranteed to be complete or accurate. Do not make any decisions or take any actions based solely on this bot's posts. You may not hold the bot, its creator, or any associated person or entity liable for any consequences or damages arising from this information or your actions or inaction based upon it. #OTX #AlienVault
OTX Bot
@techbot@social.raytec.co
social.raytec.co
Analysis of Gamaredon campaign targeting Ukraine weaponizing CVE-2025-8088
A campaign exploiting the WinRAR path-traversal vulnerability CVE-2025-8088 has been actively targeting Ukraine since February 2026, with ongoing activity through June 2026. The operation uses Ukrainian military and conscription-themed documents as lures, distributed as RAR archives. The malicious archives contain NTFS alternate data streams with path-traversal sequences that automatically place LNK files into the Windows Startup folder upon extraction. These shortcuts execute hidden PowerShell stagers incorporating anti-analysis techniques including debugger checks, disk-space verification, and sleep delays to evade sandbox detection. The persistent nature of the attacks demonstrates continuous targeting of Ukrainian entities over a four-month period using social engineering focused on military documentation themes.
Pulse ID: 6a34c6344468a941c924c02c
Pulse Link: https://otx.alienvault.com/pulse/6a34c6344468a941c924c02c
Pulse Author: AlienVault
Created: 2026-06-19 04:31:48
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #Gamaredon #InfoSec #LNK #Military #OTX #OpenThreatExchange #PowerShell #RAT #SocialEngineering #UK #Ukr #Ukraine #Ukrainian #Vulnerability #WinRAR #Windows #bot #AlienVault
You've seen all posts