Hackers Still Using Patched WinRAR Flaw for Malware Drops, Warns Google
ID: a999957f-14e1-57aa-bdc9-4184d2bb2708
STIX ID: report--a999957f-14e1-57aa-bdc9-4184d2bb2708
Feed Name: HackRead
GTIG warns that CVE-2025-8088 — a WinRAR path-traversal vulnerability — has been actively exploited in the wild by nation-state and criminal groups to install backdoors, RATs, and info-stealers via malicious archives (e.g., dropping files into the Startup folder). The report details multiple APTs and criminal campaigns leveraging the flaw, shows exploitation timelines, notes an underground seller offering the exploit, and urges users to update WinRAR to 7.13 or later to mitigate the risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
