A “known old problem” with WinRAR is proving it never really goes away. Security researchers say Russian-linked threat actors are actively exploiting the WinRAR path traversal vulnerability CVE-2025-8088 to breach targets in Ukraine—specifically government, military, and related organizations. This story goes back to last July: Rarlab released a fix for CVE-2025-8088, but WinRAR lacks strong automatic update behavior. As a result, many users never upgraded—leaving a long-lived weakness that multiple groups have continued to use. New findings show the exploit is now being used in more mission-focused campaigns. At least two Russian groups appear to have “handed off” the technique over different time windows. One group (Gamaredon / UAC-0010 / Shuckworm / Earth Dahu) is linked to delivering malicious HTA files, and researchers also observed possible persistence via VBS/VBE scripts and use of a Cloudflare Tunnel setup to stage/trigger the HTA. Another group (UAC-0226 / Shadow-Earth-066) began spreading a credential-stealing payload (GiftedCrook) via the same CVE starting in February, continuing through at least April. If you haven’t updated WinRAR: do it now. Also scrutinize HTA/script delivery, suspicious persistence, and tunnel-like connections. #CyberSecurity #WinRAR #CVE2025 #ThreatIntel #Malware #Ukraine
Want to learn more? Visit Explore the world, stay updated on travel insights and international affairs, and discover authentic stories from real life
评论
发表评论