logo

Everybody is WinRAR phishing, dropping RATs as fast as lightning

ID: 8e9ce581-1f14-5660-a58d-d5c17075224b

STIX ID: report--8e9ce581-1f14-5660-a58d-d5c17075224b

Feed Name: The Register (Security)

Threat Score
88/100

Date Published: 2026-01-28

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

Multiple government-backed and criminal groups have actively exploited a WinRAR path traversal vulnerability (CVE-2025-8088, CVSS 8.8) to hide and drop Remote Access Trojans and information-stealing malware via malicious RAR archives and Alternate Data Streams; targets include Ukrainian military, government and technology entities as well as commercial sectors worldwide. Google Threat Intelligence and ESET attribute exploitation to RomCom and several Kremlin-linked APTs, note PRC-linked delivery of PoisonIvy, and observe financially motivated gangs distributing commodity RATs/stealers; the vulnerability was patched in WinRAR 7.13 but exploit code and zero-day sales remain a concern.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.