cloud.google.com
Exploitation of WinRAR CVE-2025-8088 Threatens Ukrainian Organizations
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Two Russia-aligned cyber campaigns are exploiting the WinRAR vulnerability CVE-2025-8088 against Ukrainian targets nearly a year after it was patched. The flaw, a path traversal vulnerability, allows attackers to write files outside the extraction directory using NTFS Alternate Data Streams. Victims receive RAR archives containing decoy documents, which, when opened, execute malicious payloads without user interaction. The first campaign is attributed to SHADOW-EARTH-066, delivering the GIFTEDCROOK information stealer, while the second is linked to Earth Dahu (Gamaredon), deploying espionage tools. Both campaigns leverage the same entry point but utilize different tools and infrastructure. The ongoing exploitation highlights the risks of unmanaged software and the slow patching rates within organizations. Organizations are urged to update their WinRAR installations to mitigate this risk.
Key Points: • CVE-2025-8088 is actively exploited by multiple Russia-aligned groups against Ukraine. • Attackers use decoy documents in RAR archives to deliver malicious payloads silently. • Organizations are advised to update WinRAR to the latest version to prevent exploitation.