WinRAR Flaw Exploited by Russia-Aligned Groups to Deploy Stealers in Ukraine
A vulnerability in WinRAR, first identified in July 2025, is being exploited by Russia-aligned cyber groups to deploy malware targeting Ukrainian organizations. The attackers, including Earth Dahu and SHADOW-EARTH-066, are leveraging a path traversal flaw to deliver information stealers and espionage modules. This ongoing exploitation highlights the continued risk posed by unpatched software and underscores the scale of cyber threats facing Ukraine.
The ongoing attacks utilize CVE-2025-8088, a path traversal vulnerability within WinRAR, allowing attackers to write files outside the intended extraction directory via NTFS Alternate Data Streams (ADS). This flaw has been exploited by both Earth Dahu and SHADOW-EARTH-066 since its initial discovery, despite patches being released in July 2025. The attackers are deploying a range of malware, including the GIFTEDCROOK information stealer and GammaPhish, to steal passwords, cookies, and sensitive documents from victims’ systems.
The campaigns involve sophisticated techniques, such as creating RAR archives containing decoy PDF documents and hidden ADS payloads, which automatically execute a PowerShell loader to launch the malware. A key change observed is the shift from Telegram as an exfiltration channel to dedicated command-and-control (C2) servers, likely due to Russia’s restrictions on Telegram. Furthermore, Sekoia has documented a related attack chain involving GammaPhish and GammaSteel, adding another layer of complexity to the threat landscape.
This exploitation of a widely used software like WinRAR, prevalent across Ukrainian organizations, represents a significant security concern. The involvement of multiple, established threat actors, alongside independent clusters, demonstrates the breadth and persistence of cyber threats targeting Ukraine. The continued use of this vulnerability highlights the importance of timely patching and robust security practices.
