logo

Months After Patch, WinRAR Bug Poised to Hit SMBs Hardest

ID: b0abb503-145a-51b8-843f-52951eb5436f

STIX ID: report--b0abb503-145a-51b8-843f-52951eb5436f

Feed Name: Dark Reading

Threat Score
80/100

Date Published: 2026-01-28

Date Updated: 2026-04-21

Author: Alexander Culafi

...
...

The report details active, widespread exploitation of WinRAR vulnerability CVE-2025-8088 (path traversal) where attackers craft malicious RAR files that abuse NTFS Alternate Data Streams to drop and execute payloads (often targeting the Windows Startup folder for persistence). Google Threat Intelligence observed both state-aligned actors (e.g., Russia-aligned RomCom and other China/Russia-linked groups) and financially motivated actors deploying commodity RATs and information stealers against commercial targets; organizations are urged to patch WinRAR immediately and consult GTIG-provided IoCs and TTPs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.