logo

Hackers Exploit WinRAR CVE-2025-8088 to Plant Startup Shortcut and Run PowerShell Loader

ID: f3f9a1dc-effe-55e7-8146-ac8619276826

STIX ID: report--f3f9a1dc-effe-55e7-8146-ac8619276826

Feed Name: GBHackers

Threat Score
80/100

Date Published: 2026-06-26

Date Updated: 2026-06-26

Author: Mayura Kathir

...
...

This report details an active campaign weaponizing WinRAR CVE-2025-8088 to plant a hidden Startup shortcut using NTFS Alternate Data Streams, launching a minimized CMD that starts hidden PowerShell processes which decode and reflectively map a headerless PE in memory. The payload implements a custom reflective mapper, collects browser credentials/cookies, Firefox profiles, VPN/keystore files and stages harvested data in user paths before exfiltration to actor infrastructure (notably 142.111.194.73:8640), and exhibits evasion and resilience measures such as generated junk code, TLS validation disabling, and randomized callback paths.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.