CVE-2025-8088, a WinRAR flaw, is still exploited by Russia-aligned groups against Ukraine. SHADOW-EARTH-066 (UAC-0226) deploys an evolved GIFTEDCROOK infostealer. Earth Dahu (Gamaredon) uses HTA + Cloudflare Workers. The flaw keeps on working (no WinRAR auto-update). trendmicro.com/en_us/resear...
Old WinRAR Flaw Fuels Attacks on Ukraine: How Unmanaged Software Keeps the Door Open
Two separate Russia-aligned campaigns are still exploiting the WinRAR flaw CVE-2025-8088 against Ukrainian organizations nearly a year after it was patched, showing how unmanaged software keeps an exp...
trendmicro.com