logo

Nation-State Hackers, Cybercriminals Weaponize Patched WinRAR Flaw Despite Six-Month-Old Fix

ID: d7740ada-7dfe-59df-89a7-7500cf061ed3

STIX ID: report--d7740ada-7dfe-59df-89a7-7500cf061ed3

Feed Name: The Cyber Express

Threat Score
90/100

Date Published: 2026-01-29

Date Updated: 2026-04-23

Author: Mihir Bagwe

...
...

Google Threat Intelligence observed widespread exploitation of a critical WinRAR path traversal vulnerability (CVE-2025-8088) enabling attackers to use Alternate Data Streams and directory traversal to write malicious payloads (LNK, HTA, BAT, CMD, etc.) into Windows Startup folders for persistent execution. Multiple Russian and Chinese state-linked groups (UNC4895/RomCom, FROZENBARENTS/APT44, TURla, CARPATHIAN/TEMP.Armageddon) and financially motivated actors leveraged the flaw to deliver backdoors and commodity RATs across geopolitical and commercial targets; exploitation continued months after patch availability and IOCs were published to aid hunting.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.