WinRAR Archive Exploit Becomes a Persistent Spy Foothold
A malicious WinRAR archive is not a one-time delivery event here. Gamaredon is using CVE-2025-8088 to leave behind downloader footholds that profile the host and then pull down different payloads based on what it finds, so blocking the initial email does not remove the access path it created.
HarfangLab says the campaign against Ukrainian state institutions has been active since at least September 2025 and has gone through a dozen spearphishing waves. It documents two VBScript downloader families, GammaDrop and GammaLoad; GammaLoad adds persistence and sends victim data to command infrastructure so the operator can choose the next payload. The infrastructure is also shifting, using Cloudflare Workers, fast-flux DNS, dynamic DNS, and attacker-controlled relays.
The risk is broader than WinRAR itself. Once the archive exploit lands, the operator gets an ongoing tasking channel on state endpoints, which turns a file-opening bug into a selective espionage platform.