Hackers Exploit WinRAR CVE-2025-8088 to Plant Startup Shortcut and Run PowerShell Loader
ID: f3f9a1dc-effe-55e7-8146-ac8619276826
STIX ID: report--f3f9a1dc-effe-55e7-8146-ac8619276826
Feed Name: GBHackers
This report details an active campaign weaponizing WinRAR CVE-2025-8088 to plant a hidden Startup shortcut using NTFS Alternate Data Streams, launching a minimized CMD that starts hidden PowerShell processes which decode and reflectively map a headerless PE in memory. The payload implements a custom reflective mapper, collects browser credentials/cookies, Firefox profiles, VPN/keystore files and stages harvested data in user paths before exfiltration to actor infrastructure (notably 142.111.194.73:8640), and exhibits evasion and resilience measures such as generated junk code, TLS validation disabling, and randomized callback paths.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
