logo

WinRAR path traversal flaw still exploited by numerous hackers

ID: 120daa62-e55a-579d-b586-28204d47c0d7

STIX ID: report--120daa62-e55a-579d-b586-28204d47c0d7

Feed Name: Bleeping Computer

Threat Score
90/100

Date Published: 2026-01-27

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Multiple state-sponsored and criminal actors are actively exploiting CVE-2025-8088, a WinRAR path-traversal vulnerability that abuses Alternate Data Streams to drop hidden payloads (LNK/HTA/BAT/CMD/scripts) and persist via Windows Startup; observed actors include UNC4895 (RomCom), APT44, TEMP.Armageddon, Turla, China-linked groups, and lower-tier cybercriminals distributing RATs and stealers, with exploit code being sold by third-party vendors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.