Vulnerabilities & Exploits · APT / Espionage

WinRAR Archive Exploit Becomes a Persistent Spy Foothold

A malicious WinRAR archive is not a one-time delivery event here. Gamaredon is using CVE-2025-8088 to leave behind downloader footholds that profile the host and then pull down different payloads based on what it finds, so blocking the initial email does not remove the access path it created.

HarfangLab says the campaign against Ukrainian state institutions has been active since at least September 2025 and has gone through a dozen spearphishing waves. It documents two VBScript downloader families, GammaDrop and GammaLoad; GammaLoad adds persistence and sends victim data to command infrastructure so the operator can choose the next payload. The infrastructure is also shifting, using Cloudflare Workers, fast-flux DNS, dynamic DNS, and attacker-controlled relays.

The risk is broader than WinRAR itself. Once the archive exploit lands, the operator gets an ongoing tasking channel on state endpoints, which turns a file-opening bug into a selective espionage platform.

1 source · May 13

CVE-2025-8088

NVD KEV

Known exploited · CISA KEV

CVSS 8.8 HIGH: a path traversal vulnerability affecting the Windows version of WinRAR allows the attackers to execute arbitrary code by crafting malicious archive files. EPSS 95% (100th percentile).

CISA federal remediation date Sep 2 · date passed

Timeline

Sources

Part of the PlainSec briefing for 2026-05-13

Every edition of this story: WinRAR Archive Exploit Becomes a Persistent Spy Foothold

More from today