APT-C-08 Hackers Exploiting WinRAR Vulnerability to Attack Government Organizations
ID: ae4dd9ac-ec93-5094-8400-52e11624980e
STIX ID: report--ae4dd9ac-ec93-5094-8400-52e11624980e
Feed Name: cybersecurityNews.com
**Executive summary:** APT-C-08 (Manlinghua/BITTER) is actively exploiting CVE-2025-6218 in WinRAR to deliver weaponized RAR archives that plant a malicious Normal.dotm Office template (MD5:4bedd8e2b66cc7d64b293493ef5b8942) into the Windows template directory, enabling macro-based persistence and remote execution (launching winnsc.exe) against government organizations in South Asia; researchers recommend immediate WinRAR patching, application allowlisting, and controls to restrict Office template macros.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
