Exploitation of WinRAR Flaw CVE-2025-8088 Targets Ukraine Amid Ongoing Cyber Campaigns
ID: 284bd1bf-071d-509b-b72c-9ce7da8a6715
STIX ID: report--284bd1bf-071d-509b-b72c-9ce7da8a6715
Feed Name: ThreatCluster
Threat Score
Two Russia-aligned campaigns are actively exploiting WinRAR's CVE-2025-8088 (path traversal, CVSS 8.4) against Ukrainian military, government, and technology targets by delivering malicious RAR archives that use NTFS ADS to silently write payloads (e.g., GIFTEDCROOK, HTA) to the Windows Startup folder for persistence; organizations are urged to apply WinRAR 7.13+, monitor for ADS/startup artifacts, and deploy email attachment defenses.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
