Months After Patch, WinRAR Bug Poised to Hit SMBs Hardest
ID: b0abb503-145a-51b8-843f-52951eb5436f
STIX ID: report--b0abb503-145a-51b8-843f-52951eb5436f
Feed Name: Dark Reading
The report details active, widespread exploitation of WinRAR vulnerability CVE-2025-8088 (path traversal) where attackers craft malicious RAR files that abuse NTFS Alternate Data Streams to drop and execute payloads (often targeting the Windows Startup folder for persistence). Google Threat Intelligence observed both state-aligned actors (e.g., Russia-aligned RomCom and other China/Russia-linked groups) and financially motivated actors deploying commodity RATs and information stealers against commercial targets; organizations are urged to patch WinRAR immediately and consult GTIG-provided IoCs and TTPs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
