Despite a patch being available for nearly a year, a critical vulnerability in the WinRAR archiving tool, tracked as CVE-2025-8088, remains a favored weapon for Russian-aligned Advanced Persistent Threat (APT) groups targeting Ukraine. A new report from Trend Micro reveals that at least two distinct Russian state-sponsored actors, Gamaredon (also known as Earth Dahu or UAC-0010) and a group tracked as SHADOW-EARTH-066 (UAC-0226), are persistently exploiting this flaw. The attackers are using specially crafted RAR archives to drop malware, including the GIFTEDCROOK infostealer and other espionage tools, onto the systems of Ukrainian government and military organizations. This campaign underscores how even old, patched vulnerabilities can remain effective initial access vectors when patch management is inconsistent.
CVE-2025-8088, a path traversal vulnerability in WinRAR (CVSS 8.4) patched in July 2025.CVE-2025-8088.The attack leverages CVE-2025-8088, which allows an attacker to write files to arbitrary locations on a victim's machine when a malicious archive is opened. The attackers use this to achieve execution via T1204.002 - Malicious File.
T1547.001 - Registry Run Keys / Startup Folder).The continued exploitation of a year-old vulnerability highlights a critical security gap. For Ukrainian government and military targets, a successful breach can lead to the theft of sensitive state secrets, military plans, and intelligence, directly impacting national security. The use of infostealers like GIFTEDCROOK can compromise official accounts, leading to further escalation and deeper network intrusion. The convergence of multiple Russian APTs on this single flaw indicates its perceived reliability and effectiveness against their targets.
No specific file hashes or C2 domains were provided in the summarized articles.
CVE-2025-8088 exploitation, such as the WinRAR process writing files to unexpected locations like the Startup folder. This is a form of File Analysis.WinRAR.exe writing files outside of the user-specified extraction path.M1051 - Update Software: The most critical mitigation is to ensure that all instances of WinRAR are updated to version 7.13 or later. This is especially important for unmanaged devices where software updates may be overlooked.M1017 - User Training: Train users to be suspicious of unsolicited email attachments, even if they appear to be simple archives. Reinforce policies against opening attachments from unknown senders.M1038 - Execution Prevention: Use application control policies to restrict the execution of unauthorized scripts or executables from common drop locations like the Startup folder or temporary directories..rar files to a more secure archiver or disabling the automatic opening of files within archives.Ensure all instances of WinRAR are updated to a patched version (7.13 or later) to eliminate the vulnerability.
Educate users about the dangers of opening unsolicited email attachments, even from seemingly harmless file types like RAR archives.
Use application control to block the execution of unauthorized files from common persistence locations like the Startup folder.
WinRAR releases version 7.13, patching CVE-2025-8088.
Gamaredon campaigns exploiting the flaw remain active through at least this date.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph β relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.