Cybercriminals and nation-state groups are exploiting a six-month old WinRAR defect
ID: 8422129b-1a9d-5c42-a103-792d9975bf58
STIX ID: report--8422129b-1a9d-5c42-a103-792d9975bf58
Feed Name: CyberScoop
Google Threat Intelligence Group warns that a path-traversal WinRAR vulnerability (CVE-2025-8088) disclosed and patched six months ago is being actively and widely exploited by a diverse set of attackers — including multiple Russia-linked state groups, at least one China-based group, and several financially motivated cybercriminals — to silently drop malware (RATs and infostealers) into critical locations such as the Windows Startup folder; Google urges installation of WinRAR updates and published IOCs to help defenders hunt for these hard-to-detect intrusions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
