Russian Hackers Are Still Exploiting a Year-Old WinRAR Flaw Against Ukraine
Want more insights like this?
Two Russia-linked hacker groups — Gamaredon and Shadow-Earth-066 — are actively exploiting a WinRAR vulnerability (CVE-2025-8088) that WinRAR patched in version 7.13 back in July 2025, targeting Ukrainian military and government organizations through weaponized phishing emails. Trend Micro, which tracks the campaigns, notes Sandworm, Turla and Void Rabisu have weaponized the same flaw.
The attacks differ in execution but share the same goal. Shadow-Earth-066 deploys the GiftedCrook stealer to harvest credentials, browser cookies and documents, while Gamaredon spear-phishes from compromised government accounts to plant espionage malware via malicious HTA files. Both abuse the path traversal flaw to write payloads into Windows Startup folders using NTFS alternate data streams.
The flaw stays dangerous because WinRAR doesn't auto-update, doesn't support Group Policy, and falls outside tools like WSUS and SCCM — leaving millions of endpoints exposed. Version 7.13 or later fixes it.
Source: Dark Reading