# WinRAR Vulnerability Remains Active Weapon in Russia-Aligned Campaign Against Ukraine


A persistent security flaw in the widely-used WinRAR compression utility continues to serve as an effective entry point for Russian-aligned cyber operations targeting Ukrainian organizations, nearly a year after patches were made available. Trend Micro has documented ongoing exploitation of CVE-2025-8088, a path traversal vulnerability, by threat groups Earth Dahu (also known as Gamaredon) and SHADOW-EARTH-066 (also tracked as UAC-0226), who are using the flaw to deliver information-stealing malware.


## The Threat


The attacks leverage CVE-2025-8088, a path traversal vulnerability in WinRAR's archive extraction functionality. By crafting specially malformed RAR files, attackers can bypass WinRAR's directory extraction protections and place arbitrary files outside their intended directories. This fundamental flaw in file handling transforms a seemingly benign archive manager into a direct path to compromised systems.


Key attack characteristics:


  • Delivery method: Malicious RAR archive files distributed via phishing or watering hole attacks
  • Primary targets: Ukrainian government agencies, critical infrastructure operators, and private sector organizations
  • Malware payload: Information-stealing trojans (stealers) designed to exfiltrate credentials, documents, and system information
  • Threat actors: Earth Dahu and SHADOW-EARTH-066, both assessed as operating with Russian state alignment
  • Duration: Active exploitation for months despite patch availability

  • ## Background and Context


    CVE-2025-8088 emerged as a significant security concern when researchers discovered that WinRAR's extraction process could be manipulated through specially crafted archive files. The vulnerability allows attackers to place files in arbitrary locations on a system—a capability that transforms a simple file extraction operation into a direct code execution pathway when combined with system execution locations.


    Timeline of the vulnerability:


    | Aspect | Date/Timeline |

    |--------|-----------|

    | Vulnerability discovery | Early 2025 |

    | Patch release | First half of 2025 |

    | Continued exploitation | Present day (nearly 12 months post-patch) |

    | Geographic focus | Ukraine and Ukrainian organizations |


    WinRAR maintains an estimated 500 million users globally, making it a high-value target for attackers. The combination of widespread deployment and the stealth potential of a file extraction utility explains why this vulnerability has remained operationally useful despite public disclosure and patch availability.


    ## Technical Details


    The vulnerability operates at a fundamental level in WinRAR's archive extraction logic. When a user extracts a RAR file, the application is expected to respect directory boundaries—extracting files only into the location specified by the user. CVE-2025-8088 bypasses this restriction through path traversal sequences.


    How the attack works:


    1. Attacker crafts a RAR archive containing a file with a malicious path (e.g., ../../system32/drivers/etc/ or similar)

    2. File is named or positioned to align with legitimate-looking data or documents

    3. User receives the archive through phishing email or compromised website

    4. Upon extraction, files are placed in system-critical directories outside the target folder

    5. Malware executes with the privileges of the user who extracted the archive


    Payload characteristics:


    The stealers deployed in these campaigns typically focus on:

  • Browser credential theft — saving passwords, session cookies, and autofill data
  • Document exfiltration — targeting Office files, PDFs, and archived emails
  • System reconnaissance — gathering network topology, installed software, and user information
  • Credential harvesting — extracting cached credentials from various Windows components

  • ## Threat Actor Attribution


    Earth Dahu (Gamaredon) represents one of Russia's most active persistent threat groups, historically focused on espionage and data collection against Ukrainian targets. The group has demonstrated consistent sophistication in supply chain attacks and exploitation of legitimate tools for malicious purposes.


    SHADOW-EARTH-066 (UAC-0226) represents a complementary threat with similar operational focus on Ukrainian organizations. The parallel campaigns by both groups suggest either coordinated intelligence priorities or opportunistic exploitation of a high-value vulnerability with reliable access potential.


    Both groups share operational characteristics:

  • Preference for living-off-the-land techniques using legitimate utilities
  • Focus on information collection over destructive operations
  • Deep understanding of Ukrainian government and infrastructure networks
  • Demonstrated patience and persistence in long-term campaigns

  • ## Implications for Organizations


    The continued exploitation of CVE-2025-8088 more than 11 months after patch release raises critical questions about patch management maturity across organizational networks.


    Risk assessment:


  • Exposure scope: Any organization using unpatched WinRAR installations faces direct exploitation risk
  • Attack vector effectiveness: The use of file extraction as an entry point is particularly insidious because users trust archive managers as inherently safe utilities
  • Persistence potential: Successfully deployed stealers provide long-term reconnaissance capability, enabling subsequent phase operations
  • Geographic concentration: While attacks focus on Ukraine, the vulnerability's universal nature means any organization globally remains technically exploitable

  • Organizations beyond Ukraine should not assume immunity. The vulnerability's reliability and the extensive distribution of WinRAR make it an attractive vector for threat actors with interests in commercial espionage, competitive intelligence, or future operations against diverse targets.


    ## Recommendations


    For security teams:


  • Immediate action: Verify all WinRAR installations are updated to patched versions; deploy updates across entire organization
  • Detection: Implement file integrity monitoring on system directories to catch suspicious file placements from extraction operations
  • Email filtering: Deploy rules to block executable RAR files and archives containing suspicious path traversal sequences
  • Endpoint detection: Monitor for WinRAR child processes spawning system utilities, an indicator of malware execution

  • For end users:


  • Update WinRAR immediately from the official vendor website
  • Treat archive files with the same caution as email attachments
  • Avoid extracting archives from untrusted sources directly to system directories
  • Be suspicious of unexpected archive files, particularly those claiming to contain documents or business data

  • For defenders in Ukraine specifically:


  • Assume compromise in any organization that received potentially malicious archives
  • Conduct credential audits and rotate sensitive access tokens
  • Monitor for unusual lateral movement and data exfiltration patterns
  • Review email gateway logs for archive file patterns consistent with known attack campaigns

  • ---


    ## HackWire Analysis


    The continued exploitation of CVE-2025-8088 nearly a year after patch availability is not simply a story about a slow patch management process—it's evidence of a fundamental mismatch between threat actor operational timelines and organizational security update cycles.


    Earth Dahu and SHADOW-EARTH-066 have identified a specific vulnerability with reliable exploitation potential against a high-value target set (Ukrainian organizations) and have committed to sustained operations despite public disclosure. This suggests that even in a highly targeted, geographically specific campaign, the barrier to successful exploitation remains remarkably low. The attackers are not racing to weaponize a zero-day; they're contentedly harvesting access from organizations that have failed to patch a known flaw.


    The pattern here connects to broader trends in Russia-aligned cyber operations. Rather than pursuing sophisticated zero-day exploitation or advanced evasion techniques, groups like Earth Dahu demonstrate consistent success through patient, methodical operations exploiting well-understood weaknesses. This approach is resource-efficient and, critically, sustainable—the vulnerability remains useful as long as unpatched systems exist.


    For organizations outside Ukraine, the real lesson is not geographic. It's sectoral. Critical infrastructure operators, government agencies, and high-value private sector organizations remain the focus of persistent espionage operations. The fact that attackers chose a consumer-grade utility vulnerability as their vehicle should prompt a serious audit: What other common, legitimate tools in your environment might be exploited through similar path traversal, archive extraction, or file handling flaws? Archive managers, ISO mounting utilities, installer frameworks, and document viewers share similar extraction-based architectures.


    Ukraine's ongoing conflict status means it will continue as the geographic center of Russian cyber operations. Organizations with Ukrainian supply chain dependencies, Ukrainian employees or contractors, or Ukrainian-related operations should treat this as a persistent threat indicator. But the vulnerability itself demands universal attention: patch this across your entire installed base, regardless of geography.


    — HackWire Editorial


    ---


    ## Related Coverage


  • Read more in our [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)