Nation-state and criminal actors leverage WinRAR flaw in attacks
ID: 06eb44e4-1dd6-5c70-93a3-23ad61bdeeb7
STIX ID: report--06eb44e4-1dd6-5c70-93a3-23ad61bdeeb7
Feed Name: Security Affairs
Threat Score
Multiple nation-state and financially motivated actors actively exploited a critical WinRAR path-traversal vulnerability (CVE-2025-8088) to deliver diverse payloads—including RomCom, NESTPACKER, STOCKSTAY, POISONIVY, commodity RATs and stealers—via malicious RAR archives and phishing lures; the vulnerability was widely adopted in underground exploit markets and remained exploited even after a patch, impacting military, government, technology, and commercial targets.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
