Gamaredon Exploits WinRAR Vulnerability in Ongoing Ukraine Campaign
ID: 70668ec0-de0e-594b-91f7-639341bca5bd
STIX ID: report--70668ec0-de0e-594b-91f7-639341bca5bd
Feed Name: ThreatCluster
Gamaredon, a Russian state‑backed APT, is actively exploiting WinRAR CVE-2025-8088 via spearphishing to deliver modular malware — including a VBScript worm that hides components in NTFS Alternate Data Streams and a PowerShell stealer — against Ukrainian government, military, and critical infrastructure; the campaign leverages legitimate cloud services for C2, has been active since at least January 2026, and defenders are advised to update WinRAR and consider full host rebuilds due to strong persistence.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
