Exploitation of WinRAR CVE-2025-8088 Threatens Ukrainian Organizations
ID: a7a46f3a-eb58-5948-8b37-c527a143ac4a
STIX ID: report--a7a46f3a-eb58-5948-8b37-c527a143ac4a
Feed Name: ThreatCluster
Threat Score
Two Russia-aligned campaigns are actively exploiting WinRAR path traversal vulnerability CVE-2025-8088 (CVSS 8.4) via NTFS Alternate Data Streams to silently drop payloads (DLL, LNK, HTA) from malicious RAR archives against Ukrainian military, government, and related organizations, delivering infostealers like GIFTEDCROOK and espionage tools; organizations are urged to update to WinRAR 7.13+, deploy ADS-aware detections, and monitor startup folders for persistence indicators.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
