logo

WinRAR Flaw Exploited by Russia-Aligned Groups to Deploy Stealers in Ukraine

ID: 96d3c66f-3751-5222-b661-5917de8fe96e

STIX ID: report--96d3c66f-3751-5222-b661-5917de8fe96e

Feed Name: The Hacker News

Threat Score
85/100

Date Published: 2026-06-09

Date Updated: 2026-06-09

Author: [email protected] (The Hacker News)

...
...

Trend Micro and Sekoia analyses show two Russia-aligned actors (Earth Dahu/Gamaredon and SHADOW-EARTH-066) have actively exploited a patched WinRAR path traversal (CVE-2025-8088) to deliver information-stealing malware and espionage toolchains against Ukrainian organizations, using ADS-based RAR payloads, LNK/PowerShell loaders, HTA→VBScript chains, and dedicated C2 infrastructure to maintain persistent access and exfiltrate credentials and documents.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.