WinRAR Flaw Exploited by Russia-Aligned Groups to Deploy Stealers in Ukraine

Summary

Two Russia-aligned cyber attack campaigns are actively exploiting a path traversal vulnerability in WinRAR (CVE-2025-8088) to target Ukrainian organizations. This exploitation is occurring nearly a year after patches for the flaw were made available, indicating persistent threats against Ukraine.

IFF Assessment

FOE

The article details active exploitation of a vulnerability by threat actors, posing a direct risk to targeted organizations.

Severity

8.8 High

CISA KEV: Listed as actively exploited. Federal patch due: September 02, 2025. Known ransomware use: Unknown.

Defender Context

This highlights the ongoing threat of exploiting known vulnerabilities, especially in the context of geopolitical conflicts. Defenders should ensure all WinRAR installations are updated to the latest version and implement strong endpoint detection and response (EDR) capabilities to identify and block suspicious file operations.

Read Full Story →