Russia-Aligned Hackers Exploit Old WinRAR Vulnerability to Target Ukrainian Organizations
ID: 434e3f7f-0fc6-57e3-b63e-cd77d839bfc4
STIX ID: report--434e3f7f-0fc6-57e3-b63e-cd77d839bfc4
Feed Name: GBHackers
This report analyzes active exploitation of WinRAR path traversal CVE-2025-8088 against Ukrainian organizations by multiple intrusion sets (notably SHADOW-EARTH-066 and Russia-aligned Earth Dahu). Attackers abuse NTFS Alternate Data Streams in RAR5 headers to silently drop startup loaders (LNK/HTA/PowerShell) and an in-memory DLL stealer that harvests browser credentials and documents, uses NT syscall-based reflective loading and HTTPS exfiltration, and evades detection; the report includes MITRE technique mappings, IOCs, and mitigation steps (update WinRAR to 7.13+, block exploit patterns at mail gateways, deploy allowlisting and EDR capable of detecting NT syscall in-memory loading).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
