Old WinRAR Flaw Still Fuels Attacks on Ukraine in 2026
ID: 2c9d4973-ecd0-54b0-9a95-5257e80b9eef
STIX ID: report--2c9d4973-ecd0-54b0-9a95-5257e80b9eef
Feed Name: securityonline.info
Trend Micro analysis shows that CVE-2025-8088, a WinRAR NTFS Alternate Data Stream path-traversal flaw patched in July 2025, continues to be exploited through 2026 by Russia-aligned actors (SHADOW-EARTH-066 and Earth Dahu/Gamaredon) against Ukrainian organizations; attackers deliver RARs that drop startup-persisted payloads (memory-resident in-memory DLL loaders or HTA scripts) to steal credentials and documents and exfiltrate data, and the persistence of this threat is amplified by WinRAR's lack of auto-update and enterprise patch coverage.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
