L'exploit di WinRAR Archive diventa un foothold persistente da spia
Un archivio WinRAR malevolo non è qui un evento di delivery una tantum. Gamaredon sta usando CVE-2025-8088 per lasciare dietro di sé foothold di downloader che profilano l'host e poi scaricano diversi payload in base a ciò che trovano, quindi bloccare l'email iniziale non rimuove il percorso di accesso che ha creato.
CVSS 8.8 HIGH: a path traversal vulnerability affecting the Windows version of WinRAR allows the attackers to execute arbitrary code by crafting malicious archive files. EPSS 94% (100º percentile).
Data di correzione federale CISA 2 set · data superata
Gamaredon's infection chain: Spoofed emails, GammaDrop and GammaLoad
Summary Investigating Gamaredon’s abuse of CVE-2025-8088, we identified a dozen waves of spearphishing emails against Ukrainian state institutions in a campaign that is still active, dating back to September 2025.