logo

The “Zeroplayer” Arsenal: WinRAR Flaw CVE-2025-8088 Weaponized by Spies

ID: 86bee296-fa79-5309-ac85-46795bdba41e

STIX ID: report--86bee296-fa79-5309-ac85-46795bdba41e

Feed Name: securityonline.info

Threat Score
85/100

Date Published: 2026-01-29

Date Updated: 2026-04-23

Author: Ddos

...
...

GTIG warns that CVE-2025-8088, a WinRAR path traversal vulnerability leveraging Windows Alternate Data Streams to hide and place payloads (often into the Startup folder), is being actively exploited by Russia- and China-linked APTs and financially motivated cybercriminals to deliver malware (POISONIVY, XWorm, AsyncRAT) across military, government, and commercial sectors; a patch (WinRAR 7.13, 30 July 2025) exists but slow patching has enabled ongoing n-day exploitation and trafficked exploits from sellers like "zeroplayer" increase risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.