Update WinRAR tools now: RomCom and others exploiting zero-day vulnerability
ID: fd308a0d-7505-5b4b-8868-0aa31c2b3ed5
STIX ID: report--fd308a0d-7505-5b4b-8868-0aa31c2b3ed5
Feed Name: WeLiveSecurity (ESET Research)
Threat Score
ESET discovered RomCom exploiting a previously unknown WinRAR zero-day (CVE-2025-8088) via ADS-based path traversal in July 2025 to silently extract malicious LNK and DLL/EXE files from spearphishing RAR attachments; the campaign targeted financial, manufacturing, defense, and logistics organizations in Europe and Canada and delivered multiple backdoors (Mythic agent, SnipBot variant, RustyClaw/MeltingClaw).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
