logo

Hackers Still Using Patched WinRAR Flaw for Malware Drops, Warns Google

ID: a999957f-14e1-57aa-bdc9-4184d2bb2708

STIX ID: report--a999957f-14e1-57aa-bdc9-4184d2bb2708

Feed Name: HackRead

Threat Score
90/100

Date Published: 2026-01-28

Date Updated: 2026-04-22

Author: Deeba Ahmed

...
...

GTIG warns that CVE-2025-8088 — a WinRAR path-traversal vulnerability — has been actively exploited in the wild by nation-state and criminal groups to install backdoors, RATs, and info-stealers via malicious archives (e.g., dropping files into the Startup folder). The report details multiple APTs and criminal campaigns leveraging the flaw, shows exploitation timelines, notes an underground seller offering the exploit, and urges users to update WinRAR to 7.13 or later to mitigate the risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.