Nation-State Hackers, Cybercriminals Weaponize Patched WinRAR Flaw Despite Six-Month-Old Fix
ID: d7740ada-7dfe-59df-89a7-7500cf061ed3
STIX ID: report--d7740ada-7dfe-59df-89a7-7500cf061ed3
Feed Name: The Cyber Express
Google Threat Intelligence observed widespread exploitation of a critical WinRAR path traversal vulnerability (CVE-2025-8088) enabling attackers to use Alternate Data Streams and directory traversal to write malicious payloads (LNK, HTA, BAT, CMD, etc.) into Windows Startup folders for persistent execution. Multiple Russian and Chinese state-linked groups (UNC4895/RomCom, FROZENBARENTS/APT44, TURla, CARPATHIAN/TEMP.Armageddon) and financially motivated actors leveraged the flaw to deliver backdoors and commodity RATs across geopolitical and commercial targets; exploitation continued months after patch availability and IOCs were published to aid hunting.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
