# Russian Threat Groups Continue Exploiting Year-Old WinRAR Vulnerability in Ukraine-Targeted Campaigns
## The Threat
At least two Russia-aligned threat clusters have weaponized a critical vulnerability in the widely-used WinRAR compression utility to launch coordinated cyberattacks against Ukrainian military and government organizations. Despite the flaw being patched nearly a year ago, threat actors continue to refine their exploitation techniques and generate new attack samples, demonstrating the persistent risk posed by unpatched systems in high-value target environments.
The vulnerability, tracked as CVE-2025-8088, was initially patched in WinRAR version 7.13 in July 2025. Yet months into 2026, Russian-backed threat groups show no signs of abandoning the exploit, instead evolving their attack chains and delivery mechanisms. Trend Micro's research, published Monday, reveals that two distinct threat actors—Shadow-Earth-066 (also tracked as UAC-0226 by Ukraine's CERT-UA) and Earth Dahu (known by alternative names including Gamaredon, Primitive Bear, Shuckworm, Aqua Blizzard, and UAC-0010)—are actively conducting separate campaigns leveraging the same vulnerability.
What makes this particular threat landscape especially concerning is not just the persistence of exploitation, but the deliberate refinement of attack methodologies. As recently as April 2026, both groups were actively generating new exploit samples, with Earth Dahu remaining actively engaged in offensive operations.
## Background and Context
The WinRAR vulnerability exploits a path traversal weakness in how the compression utility handles specially-crafted RAR files. When a user extracts a maliciously-designed archive, the flaw allows attackers to place executable files outside the intended extraction directory—a technique that can lead to arbitrary code execution on the victim's system.
Timeline of events:
| Date | Event |
|------|-------|
| July 2025 | Vulnerability patched in WinRAR 7.13 |
| Early 2026 | Shadow-Earth-066 and Earth Dahu observed exploiting CVE-2025-8088 |
| April 2026 | Both threat groups generating new exploit samples |
| June 9, 2026 | Trend Micro publishes detailed analysis of dual campaigns |
The vulnerability's attractiveness to threat actors lies partly in WinRAR's ubiquity in Ukrainian organizations. The compression utility is deeply embedded in daily operations across government agencies, military institutions, and critical infrastructure—making it an ideal infection vector for espionage and data theft campaigns targeting these sectors.
Notably, this is not the first time Russian-aligned groups have exploited CVE-2025-8088. Earlier analysis by Google's Threat Intelligence Group documented exploitation by additional Russia-backed threat actors, including Sandworm (the group behind NotPetya), Turla (a long-running state-sponsored APT), and Void Rabisu—indicating this vulnerability has achieved widespread adoption across Russia's cyber operations establishment.
## Technical Details
The two observed campaigns diverge significantly in their post-exploitation attack chains, despite both beginning with weaponized email delivery:
### Shadow-Earth-066 Campaign
Shadow-Earth-066's attack chain focuses on information stealing and credential harvesting:
1. Initial delivery: Malicious email containing a crafted RAR archive
2. Exploitation: CVE-2025-8088 extracts files outside intended directory
3. Payload: Updated version of GiftedCrook information stealer
4. Capabilities:
- Harvests credentials from compromised systems
- Exfiltrates documents and sensitive files
- Self-deletes after completing theft operations
5. Evasion: The self-deletion mechanism removes evidence of compromise
### Earth Dahu Campaign
Earth Dahu's approach emphasizes long-term espionage and persistent access:
1. Initial delivery: Weaponized email with malicious RAR attachment
2. Exploitation: CVE-2025-8088 vulnerability execution
3. Infection chain: Delivers HTML applications (HTAs) that facilitate further infection
4. Capabilities:
- Establishes persistent backdoor access
- Enables remote code execution
- Supports multi-stage malware deployment
5. Targeting focus: Military innovation centers, military formations, law enforcement agencies
The use of HTML applications (HTAs) in Earth Dahu's chain is particularly noteworthy. HTAs are legitimate Windows utilities that can execute VBScript or JavaScript, providing a living-off-the-land technique that evades many traditional endpoint security controls.
## Implications for Organizations
The continued exploitation of a patched vulnerability highlights several critical risk factors:
Patch deployment lag remains widespread: Nearly a year after the fix was released, Ukrainian organizations still run vulnerable versions of WinRAR. This gap between patch release and deployment—sometimes measured in months—creates extended vulnerability windows that determined threat actors will exploit.
Geopolitical targeting increases urgency: This is not a mass-market exploitation scenario. The attacks specifically target Ukrainian military and government entities, indicating state-sponsored or state-aligned threat activity focused on wartime intelligence collection and operational disruption.
Supply chain risk in utilities: WinRAR's position as a ubiquitous productivity tool—often installed without explicit security vetting—makes it an ideal attack surface. Organizations frequently prioritize functionality and employee productivity over timely security updates for such tools.
Multiple threat actor adoption signals maturity: The fact that at least five distinct Russian-aligned threat clusters have adopted CVE-2025-8088 exploitation suggests the vulnerability has achieved status as a standard tool in Russia's offensive toolkit, comparable to other widely-used exploits.
## Recommendations
Organizations should implement immediate and sustained controls:
1. Patch Management
2. Email Security
3. Detection and Response
4. Access Controls
5. Threat Intelligence Integration
## HackWire Analysis
The persistence of CVE-2025-8088 exploitation nine months after patching reveals a critical gap between security theory and operational reality. In cybersecurity discourse, we treat patch release as the narrative endpoint—the story ends when the vendor fixes the code. But in real-world defense, patch release is merely the beginning of a race between defenders and attackers, a race that Ukrainian organizations are clearly losing.
What's particularly striking here is not that a patched vulnerability is still being exploited—that's routine. Rather, it's the *scale and sophistication* of adoption across multiple Russian threat groups. CVE-2025-8088 has graduated from "interesting exploit" to "operational standard," like Mimikatz or PSExec before it. This represents a fundamental degradation in the operational security posture of Ukrainian targets.
The dual campaign structure is also instructive. Shadow-Earth-066 appears focused on data theft—credentials, documents, rapid exfiltration and cleanup. Earth Dahu, by contrast, is building persistent access through HTAs. This suggests different operational objectives: one group running smash-and-grab intelligence collection, the other positioning for long-term surveillance. Both approaches are likely valid for different intelligence priorities across Russian cyber operations.
The hidden risk here is complacency around "mature" vulnerabilities. WinRAR isn't Microsoft Exchange or Windows itself—it's treated as peripheral utility software. Organizations delay patching utilities longer than OS patches, support teams lack visibility into all installations, and endpoint security tools sometimes deprioritize threats that don't directly target Windows kernel or application frameworks. Threat actors have clearly identified this behavioral blind spot and are exploiting it systematically.
For defenders, the lesson is ruthless: treat every software category with the same patch discipline you apply to critical infrastructure. WinRAR's ubiquity is a feature for attackers precisely because organizations treated it as infrastructure-grade risk (it isn't) rather than software-grade risk (it is).
— HackWire Editorial
## Related Coverage