logo

Nation-state and criminal actors leverage WinRAR flaw in attacks

ID: 06eb44e4-1dd6-5c70-93a3-23ad61bdeeb7

STIX ID: report--06eb44e4-1dd6-5c70-93a3-23ad61bdeeb7

Feed Name: Security Affairs

Threat Score
90/100

Date Published: 2026-01-29

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

Multiple nation-state and financially motivated actors actively exploited a critical WinRAR path-traversal vulnerability (CVE-2025-8088) to deliver diverse payloads—including RomCom, NESTPACKER, STOCKSTAY, POISONIVY, commodity RATs and stealers—via malicious RAR archives and phishing lures; the vulnerability was widely adopted in underground exploit markets and remained exploited even after a patch, impacting military, government, technology, and commercial targets.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.