logo

Update WinRAR tools now: RomCom and others exploiting zero-day vulnerability

ID: fd308a0d-7505-5b4b-8868-0aa31c2b3ed5

STIX ID: report--fd308a0d-7505-5b4b-8868-0aa31c2b3ed5

Feed Name: WeLiveSecurity (ESET Research)

Threat Score
90/100

Date Published: 2025-08-11

Date Updated: 2026-05-01

...
...

ESET discovered RomCom exploiting a previously unknown WinRAR zero-day (CVE-2025-8088) via ADS-based path traversal in July 2025 to silently extract malicious LNK and DLL/EXE files from spearphishing RAR attachments; the campaign targeted financial, manufacturing, defense, and logistics organizations in Europe and Canada and delivered multiple backdoors (Mythic agent, SnipBot variant, RustyClaw/MeltingClaw).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.