WinRAR Flaw Exploited by Russia-Aligned Groups to Deploy Stealers in Ukraine
ID: 96d3c66f-3751-5222-b661-5917de8fe96e
STIX ID: report--96d3c66f-3751-5222-b661-5917de8fe96e
Feed Name: The Hacker News
Threat Score
Trend Micro and Sekoia analyses show two Russia-aligned actors (Earth Dahu/Gamaredon and SHADOW-EARTH-066) have actively exploited a patched WinRAR path traversal (CVE-2025-8088) to deliver information-stealing malware and espionage toolchains against Ukrainian organizations, using ADS-based RAR payloads, LNK/PowerShell loaders, HTA→VBScript chains, and dedicated C2 infrastructure to maintain persistent access and exfiltrate credentials and documents.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
