logo

APT-C-08 Hackers Exploiting WinRAR Vulnerability to Attack Government Organizations

ID: ae4dd9ac-ec93-5094-8400-52e11624980e

STIX ID: report--ae4dd9ac-ec93-5094-8400-52e11624980e

Feed Name: cybersecurityNews.com

Threat Score
88/100

Date Published: 2025-11-12

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

**Executive summary:** APT-C-08 (Manlinghua/BITTER) is actively exploiting CVE-2025-6218 in WinRAR to deliver weaponized RAR archives that plant a malicious Normal.dotm Office template (MD5:4bedd8e2b66cc7d64b293493ef5b8942) into the Windows template directory, enabling macro-based persistence and remote execution (launching winnsc.exe) against government organizations in South Asia; researchers recommend immediate WinRAR patching, application allowlisting, and controls to restrict Office template macros.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.