WinRAR Zero-Day CVE-2025-8088 Exploited to Spread RomCom Malware
ID: 0b734694-9a31-5f5e-81cb-26f4f022f796
STIX ID: report--0b734694-9a31-5f5e-81cb-26f4f022f796
Feed Name: HackRead
Threat Score
WinRAR suffered a critical path-traversal vulnerability (CVE-2025-8088) that was actively exploited by a Russia-linked cyberespionage group to deliver the RomCom backdoor through crafted archive attachments in phishing emails; ESET researchers disclosed the abuse and WinRAR released version 7.13 to fix the flaw, but users must manually install the update to remain protected.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
