Security researchers report that two Russia-aligned hacking campaigns are exploiting a WinRAR vulnerability that was patched nearly a year ago to target Ukrainian organizations. The activity centers on CVE-2025-8088, described as a path traversal flaw in WinRAR. According to Trend Micro research cited by multiple outlets, the flaw is being used in ongoing intrusions aimed at Ukrainian government and military targets. The campaigns use the vulnerability to deliver malware designed to steal credentials and support cyberespionage. The reporting identifies two threat groups attributed by Trend Micro: Earth Dahu (also known as Gamaredon) and SHADOW-EARTH-066 (also known as UAC-0226). One outlet notes the vulnerability’s CVSS score as 8.4, indicating high severity. The campaigns are described as separate efforts that continue after the vulnerability was fixed last July, with attackers leveraging the still-unpatched systems or instances despite the earlier remediation. Overall, the coverage aligns on the same vulnerability, the Ukrainian target focus, and the Russia-linked attribution for the groups involved.
Russia-Linked Groups Exploit Patched WinRAR Flaw to Target Ukraine
Security researchers report that two Russia-aligned hacking campaigns are exploiting a WinRAR vulnerability that was patched nearly a year ago to target Ukrainian organizations. The activity centers o...
- Researchers say two Russia-aligned groups exploit a WinRAR vulnerability to attack Ukrainian targets.
- The exploited flaw is CVE-2025-8088, described as a path traversal issue.
- Trend Micro attributes activity to Earth Dahu (Gamaredon) and SHADOW-EARTH-066 (UAC-0226).
- The campaigns use the flaw to deploy credential-stealing malware and support espionage.
- Multiple reports say patches were released nearly a year earlier, including a fix last July.
Two Russian state-linked hacking groups are actively exploiting a path traversal vulnerability in WinRAR that was patched nearly a year ago, using it to deploy credential-stealing malware against Ukrainian government and military targets, according to research published by Trend Micro. The flaw, tracked as CVE-2025-8088 and rated 8.4 on the CVSS scale, allows attackers to […] This story continues at The Next Web
2 months agoTwo separate campaigns target CVE-2025-8088, fixed last July, to conduct data theft and cyberespionage against military and government targets in Ukraine.
2 months agoTwo Russia-aligned cyber attack campaigns have continued to exploit a security flaw in WinRAR to target Ukrainian organisations, almost a year after patches for the vulnerability were released. The activity has been attributed by Trend Micro to Earth Dahu (aka Gamaredon) and SHADOW-EARTH-066 (aka UAC-0226). It involves the exploitation of CVE-2025-8088, a path traversal flaw that allows an
2 months agoSAPS data shows which provinces report highest murder, rape and carjacking
South African Police Service (SAPS) crime statistics for April to June 2026 show clear differences across provinces for...
Nepal flood rescues intensify as over 500 people remain unaccounted at hydropower sites
Rescue teams in Nepal are intensifying efforts after floods disrupt hydropower projects, with reports stating that more...
Hospice arranges wedding for dying husband; wife expresses gratitude
A Wicklow hospice arranges a wedding for a woman’s husband during his final weeks, and his wife says she is grateful for...