news.mlab.sh
Back to the feed
threat-intel

Russian Attackers Weaponize WinRAR Flaw Against Ukrainian Orgs

High
Summary

Russian threat actors, including Shadow-Earth-066 (UAC-0226) and Earth Dahu (Primitive Bear, Shuckworm), are continuing to exploit a long-standing vulnerability (CVE-2025-8088) in WinRAR to conduct data theft and cyber espionage against Ukrainian government and military organizations. Despite the vulnerability being patched nearly a year ago, unpatched systems remain a target due to WinRAR's widespread use and the relatively simple nature of the exploit. Other state-sponsored groups like Sandworm and Turla have also leveraged this flaw.

The ongoing attacks utilize email-based campaigns to deliver malicious WinRAR archive files containing the CVE-2025-8088 vulnerability. Attackers then leverage this flaw to execute arbitrary code, allowing them to deploy malware such as the GiftedCrook information stealer and espionage-focused HTML applications (HTAs). The vulnerability allows attackers to place malicious shortcuts or payloads in Windows Startup locations, enabling code execution after login. This tactic is particularly concerning given WinRAR's prevalence across Ukrainian organizations and the global user base. Recent findings from Google's Threat Intelligence Group highlight that state-sponsored actors, including Sandworm, Turla, and Void Rabisu, have also been targeting this vulnerability, further emphasizing its continued relevance in the threat landscape. The attackers' persistence underscores the importance of timely patching and robust security measures.

Read the full article at Dark Reading