logo

Russia-Aligned Hackers Exploit Old WinRAR Vulnerability to Target Ukrainian Organizations

ID: 434e3f7f-0fc6-57e3-b63e-cd77d839bfc4

STIX ID: report--434e3f7f-0fc6-57e3-b63e-cd77d839bfc4

Feed Name: GBHackers

Threat Score
85/100

Date Published: 2026-06-15

Date Updated: 2026-06-15

Author: Mayura Kathir

...
...

This report analyzes active exploitation of WinRAR path traversal CVE-2025-8088 against Ukrainian organizations by multiple intrusion sets (notably SHADOW-EARTH-066 and Russia-aligned Earth Dahu). Attackers abuse NTFS Alternate Data Streams in RAR5 headers to silently drop startup loaders (LNK/HTA/PowerShell) and an in-memory DLL stealer that harvests browser credentials and documents, uses NT syscall-based reflective loading and HTTPS exfiltration, and evades detection; the report includes MITRE technique mappings, IOCs, and mitigation steps (update WinRAR to 7.13+, block exploit patterns at mail gateways, deploy allowlisting and EDR capable of detecting NT syscall in-memory loading).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.