logo

Russian Attackers Weaponize WinRAR Flaw Against Ukrainian Orgs

ID: b632833a-3cde-56d1-8c11-e290e097d646

STIX ID: report--b632833a-3cde-56d1-8c11-e290e097d646

Feed Name: Dark Reading

Threat Score
88/100

Date Published: 2026-06-09

Date Updated: 2026-06-15

Author: Elizabeth Montalbano

...
...

Trend Micro and other telemetry show Russia-aligned actors are actively exploiting WinRAR path-traversal CVE-2025-8088 to deliver credential-stealing and espionage malware against Ukrainian military and government targets; attacks begin with phishing emails containing weaponized RAR archives that place LNK/HTA files into Windows Startup locations (leading to GiftedCrook and HTA-based loader chains), and persist because many endpoints remain unpatched despite a July 2025 patch.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.