Vulnerabilities · 97 days ago

WinRAR Patched, But Ukraine Is Still Getting Hit

WinRAR is being used as a durable delivery path, not a one-time bad archive. Once the file lands outside the extraction folder and into Windows Startup, the next login gives the attacker persistence, credential theft, and a clean exit that wipes the local trail after exfiltration.

Trend Micro says Earth Dahu and SHADOW-EARTH-066 are still exploiting CVE-2025-8088 against Ukrainian military, government, law enforcement, and related organizations months after WinRAR 7.13 shipped in July 2025. One campaign moved from Excel macros to archive-delivered stealers; the other used the flaw to drop espionage malware, with targets including passwords, browser cookies, and documents. A separate note from the report is that unmanaged WinRAR installs keep the entry point open long after the fix exists.

The risk now is not just the original vulnerability. It is the combination of email-delivered archives, startup persistence, and self-deleting malware that can survive routine cleanup and leave stolen credentials as the real foothold.

CVE-2025-8088

NVD KEV

Known exploited · CISA KEV

CVSS 8.8 HIGH: a path traversal vulnerability affecting the Windows version of WinRAR allows the attackers to execute arbitrary code by crafting malicious archive files. EPSS 95% (100th percentile).

CISA federal remediation date Sep 2 · date passed

Timeline

Sources

2 sources covering this story

Entities

Vendor digest: Microsoft

Part of the PlainSec briefing for 2026-06-10

Editions

Related stories