Exploitation of WinRAR CVE-2025-8088 Threatens Ukrainian Organizations

Exploitation of WinRAR CVE-2025-8088 Threatens Ukrainian Organizations

First seen 8 Jun 2026, 11:17 UTC Trendmicrocloud.google.comRescanaFeeds.4SysopsDarkreading+11 87% similarity 78.0

Article Content

Browse articles
ThreatCluster

Two Russia-aligned cyber campaigns are exploiting the WinRAR vulnerability CVE-2025-8088 against Ukrainian targets nearly a year after it was patched. The flaw, a path traversal vulnerability, allows attackers to write files outside the extraction directory using NTFS Alternate Data Streams. Victims receive RAR archives containing decoy documents, which, when opened, execute malicious payloads without user interaction. The first campaign is attributed to SHADOW-EARTH-066, delivering the GIFTEDCROOK information stealer, while the second is linked to Earth Dahu (Gamaredon), deploying espionage tools. Both campaigns leverage the same entry point but utilize different tools and infrastructure. The ongoing exploitation highlights the risks of unmanaged software and the slow patching rates within organizations. Organizations are urged to update their WinRAR installations to mitigate this risk.

Key Points: • CVE-2025-8088 is actively exploited by multiple Russia-aligned groups against Ukraine. • Attackers use decoy documents in RAR archives to deliver malicious payloads silently. • Organizations are advised to update WinRAR to the latest version to prevent exploitation.

ThreatCluster AI

Timeline

2019-02-05
CVE-2018-20250 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2023-07-11
CVE-2023-36884 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2023-08-23
CVE-2023-38831 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2025-07-18
Exploitation of CVE-2025-8088 observed
Malicious DLLs were found in RAR archives, indicating exploitation by RomCom and others.
www.welivesecurity.com
2025-07-30
WinRAR version 7.13 released
The vulnerability CVE-2025-8088 was patched in this version, addressing the path traversal flaw.
www.welivesecurity.com
2025-08-08
CVE-2025-8088 published
The vulnerability was officially disclosed and documented, marking its existence in security databases.
Date unknown
2025-12-09
CISA adds CVE-2025-6218 to KEV
CISA recognized the active exploitation of CVE-2025-6218, related to earlier WinRAR vulnerabilities.
Date unknown
2026-06-08
Ongoing exploitation reported
Two separate campaigns continue to exploit CVE-2025-8088 against Ukrainian organizations, nearly a year post-patch.
Trendmicro

Community

Browse all →