WinRAR Flaw Exploited by Russia-Aligned Groups to Deploy Stealers in Ukraine

Read full story on The Hacker News
Share
WinRAR Flaw Exploited by Russia-Aligned Groups to Deploy Stealers in Ukraine
AI disclosure

Summary

Two Russia-aligned cyber attack campaigns have continued to exploit a security flaw in WinRAR to target Ukrainian organisations, almost a year after patches for the vulnerability were released. The activity has been attributed by Trend Micro to Earth Dahu (aka Gamaredon) and SHADOW-EARTH-066 (aka UAC-0226). It involves the exploitation of CVE-2025-8088, a path traversal flaw that allows an

Original reporting

Open original source

Related coverage

Read full article on The Hacker News

Get the AFBytes Brief

Major stories, AI-assisted analysis, and what to watch next. Free, monthly, unsubscribe anytime.