WinRAR path traversal flaw still exploited by numerous hackers
ID: 120daa62-e55a-579d-b586-28204d47c0d7
STIX ID: report--120daa62-e55a-579d-b586-28204d47c0d7
Feed Name: Bleeping Computer
Threat Score
Multiple state-sponsored and criminal actors are actively exploiting CVE-2025-8088, a WinRAR path-traversal vulnerability that abuses Alternate Data Streams to drop hidden payloads (LNK/HTA/BAT/CMD/scripts) and persist via Windows Startup; observed actors include UNC4895 (RomCom), APT44, TEMP.Armageddon, Turla, China-linked groups, and lower-tier cybercriminals distributing RATs and stealers, with exploit code being sold by third-party vendors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
