Russian Attackers Weaponize WinRAR Flaw Against Ukrainian Orgs
ID: b632833a-3cde-56d1-8c11-e290e097d646
STIX ID: report--b632833a-3cde-56d1-8c11-e290e097d646
Feed Name: Dark Reading
Threat Score
Trend Micro and other telemetry show Russia-aligned actors are actively exploiting WinRAR path-traversal CVE-2025-8088 to deliver credential-stealing and espionage malware against Ukrainian military and government targets; attacks begin with phishing emails containing weaponized RAR archives that place LNK/HTA files into Windows Startup locations (leading to GiftedCrook and HTA-based loader chains), and persist because many endpoints remain unpatched despite a July 2025 patch.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
