WinRAR Patched, But Ukraine Is Still Getting Hit

WinRAR is being used as a durable delivery path, not a one-time bad archive. Once the file lands outside the extraction folder and into Windows Startup, the next login gives the attacker persistence, credential theft, and a clean exit that wipes the local trail after exfiltration. Trend Micro says Earth Dahu and SHADOW-EARTH-066 are still exploiting CVE-2025-8088 against Ukrainian military, government, law enforcement, and related organizations months after WinRAR 7.13 shipped in July 2025. One campaign moved from Excel macros to archive-delivered stealers; the other used the flaw to drop espionage malware, with targets including passwords, browser cookies, and documents. A separate note from the report is that unmanaged WinRAR installs keep the entry point open long after the fix exists. The risk now is not just the original vulnerability. It is the combination of email-delivered archives, startup persistence, and self-deleting malware that can survive routine cleanup and leave stolen credentials as the real foothold.

Part of the PlainSec briefing for 2026-06-10

Sources