logo

Russian APTs Still Exploiting Patched WinRAR Flaw CVE-2025-8088

ID: e50e4204-fb02-55c5-bf25-e0a4876a53e4

STIX ID: report--e50e4204-fb02-55c5-bf25-e0a4876a53e4

Feed Name: Security Affairs

Threat Score
90/100

Date Published: 2026-06-10

Date Updated: 2026-06-10

Author: Pierluigi Paganini

...
...

Trend Micro and related reporting describe Russian-linked APTs exploiting a patched WinRAR path traversal (CVE-2025-8088) to deliver malware via phishing RAR archives: SHADOW-EARTH-066 uses a multi-stage, memory-only DLL stealer that harvests browser credentials and files and exfiltrates via dedicated C2s, while Earth Dahu (Gamaredon) drops HTA/VBScript loaders pulling modules via Cloudflare Workers; exploitation persists due to WinRAR's lack of auto-update and poor enterprise coverage.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.