logo

Old WinRAR Flaw Still Fuels Attacks on Ukraine in 2026

ID: 2c9d4973-ecd0-54b0-9a95-5257e80b9eef

STIX ID: report--2c9d4973-ecd0-54b0-9a95-5257e80b9eef

Feed Name: securityonline.info

Threat Score
85/100

Date Published: 2026-06-15

Date Updated: 2026-06-15

Author: Do Son

...
...

Trend Micro analysis shows that CVE-2025-8088, a WinRAR NTFS Alternate Data Stream path-traversal flaw patched in July 2025, continues to be exploited through 2026 by Russia-aligned actors (SHADOW-EARTH-066 and Earth Dahu/Gamaredon) against Ukrainian organizations; attackers deliver RARs that drop startup-persisted payloads (memory-resident in-memory DLL loaders or HTA scripts) to steal credentials and documents and exfiltrate data, and the persistence of this threat is amplified by WinRAR's lack of auto-update and enterprise patch coverage.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.