logo

Exploitation of WinRAR Flaw CVE-2025-8088 Targets Ukraine Amid Ongoing Cyber Campaigns

ID: 284bd1bf-071d-509b-b72c-9ce7da8a6715

STIX ID: report--284bd1bf-071d-509b-b72c-9ce7da8a6715

Feed Name: ThreatCluster

Threat Score
75/100

Date Published: 2026-06-08

Date Updated: 2026-06-08

...
...

Two Russia-aligned campaigns are actively exploiting WinRAR's CVE-2025-8088 (path traversal, CVSS 8.4) against Ukrainian military, government, and technology targets by delivering malicious RAR archives that use NTFS ADS to silently write payloads (e.g., GIFTEDCROOK, HTA) to the Windows Startup folder for persistence; organizations are urged to apply WinRAR 7.13+, monitor for ADS/startup artifacts, and deploy email attachment defenses.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.