Earth Estries alive and kicking
ID: ff0da4b3-238d-5830-9267-d7465ed44aa4
STIX ID: report--ff0da4b3-238d-5830-9267-d7465ed44aa4
Feed Name: Blaze's Security Blog
Threat Score
The report outlines an Earth Estries (aka Salt Typhoon) campaign abusing a recent WinRAR vulnerability (CVE-2025-8088) to achieve shellcode execution, leveraging fake PDFs, DLL hijacking, and scheduled tasks to deploy payloads and contact external infrastructure. It provides concrete indicators of compromise (hashes, filenames, IP/domain), associated YARA rules, and references for further analysis, enabling detection and response.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
