cloud.google.com Exploitation of WinRAR CVE-2025-8088 Threatens Ukrainian Organizations
Article Content
- •CVE-2025-8088 is actively exploited by multiple Russia-aligned groups against Ukraine.
- •Attackers use decoy documents in RAR archives to deliver malicious payloads silently.
- •Organizations are advised to update WinRAR to the latest version to prevent exploitation.
Two Russia-aligned cyber campaigns are exploiting the WinRAR vulnerability CVE-2025-8088 against Ukrainian targets nearly a year after it was patched. The flaw, a path traversal vulnerability, allows attackers to write files outside the extraction directory using NTFS Alternate Data Streams. Victims receive RAR archives containing decoy documents, which, when opened, execute malicious payloads without user interaction. The first campaign is attributed to SHADOW-EARTH-066, delivering the GIFTEDCROOK information stealer, while the second is linked to Earth Dahu (Gamaredon), deploying espionage tools. Both campaigns leverage the same entry point but utilize different tools and infrastructure. The ongoing exploitation highlights the risks of unmanaged software and the slow patching rates within organizations. Organizations are urged to update their WinRAR installations to mitigate this risk.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (20)
Following this threat?
Track APT28, Giftedcrook and CVE-2018-20250 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Trellix Reports on Five Evasive Cyber Campaigns in 2026 Trellix's SecondSight Threat Hunting Report details five significant cyber campaigns from the first half of 2026, including APT28 and the Axios npm supply chain attack. Attackers exploited trusted infrastructures and employed advanced evasion techniques, such as using compromised government accounts and weaponizing…
2026 AV-Comparatives EPR Test Results Released AV-Comparatives published the results of its 2026 Endpoint Prevention and Response (EPR) Test, evaluating 14 enterprise security products against 50 multi-stage attack scenarios. The test, which ran from May to August 2026, incorporated AI-assisted techniques and followed the MITRE ATT&CK framework. Eleven products…