Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
Back to intelligence
actively-exploited-vulnerabilityendpoint-software-vulnerabilitystate-sponsored-espionageinitial-access-method

Ongoing Exploitation of WinRAR Path Traversal Vulnerability CVE-2025-8088

Updated 13h agoFirst seen Jan 28, 202612 sources

Google Threat Intelligence Group (GTIG) reported ongoing, widening exploitation of a high-severity WinRAR path traversal flaw, CVE-2025-8088, roughly six months after it was disclosed and patched by RARLAB. GTIG assessed exploitation began as early as July 18, 2025 (including activity nearly two weeks before the vendor fix) and has expanded across a diverse set of adversaries, spanning Russia- and China-linked espionage actors as well as financially motivated cybercriminals. Reported targeting includes military, government, and technology organizations, with multiple Russia-aligned operations focusing on Ukrainian entities.

Technical reporting indicates the vulnerability abuses Windows Alternate Data Streams (ADS) within crafted archives to perform directory traversal and write files to arbitrary locations, including the Windows Startup folder for persistence. GTIG and other researchers describe exploit chains where a user opens a benign decoy (e.g., a PDF) while hidden ADS entries extract and drop executable content such as LNK, HTA, BAT, CMD, or script files that run at login; observed payloads include remote access trojans, infostealers, and malware frameworks used by named state actors (e.g., RomCom/UNC4895, APT44, TEMP.Armageddon, Turla) in addition to broader criminal activity across multiple regions.

Share:
Ongoing Exploitation of WinRAR Path Traversal Vulnerability CVE-2025-8088
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

10 events from the most recent confirmed update back to the earliest known activity.

10 EVENTS
Jan 28, 20265mo ago

Researchers warn CVE-2025-6218 is also seeing exploitation attempts

Alongside its reporting on CVE-2025-8088, Google warned in late January 2026 that another WinRAR flaw, CVE-2025-6218, was also facing exploitation attempts by multiple actors. This reinforced concerns about attackers' continued use of patched WinRAR vulnerabilities.

Jan 27, 20265mo ago

Google reports widespread ongoing exploitation into 2026

In late January 2026, Google Threat Intelligence Group published findings that CVE-2025-8088 was still being actively exploited roughly six months after patching by a mix of nation-state and financially motivated actors. Google also published indicators of compromise and urged organizations to update WinRAR and hunt for related activity.

Aug 1, 202511mo ago

Underground seller 'zeroplayer' markets WinRAR exploit access

An exploit supplier using the name 'zeroplayer' was reported advertising a WinRAR zero-day/exploit in 2025, with some reports citing a price of $80,000. Researchers assessed this exploit-supply activity helped multiple state and criminal actors obtain and operationalize the capability.

Financially motivated actors adopt the exploit for commodity malware

Multiple criminal groups began using CVE-2025-8088 to distribute commodity RATs, stealers, Telegram bot-controlled backdoors, and phishing tooling. Reported victim sectors and regions included hospitality, banking, Indonesia, South America, and LATAM, including campaigns targeting Brazilian banking users with a malicious Chrome extension.

China-linked actor uses flaw to deliver PoisonIvy

Google linked a PRC-based threat actor to exploitation of CVE-2025-8088 to deploy PoisonIvy, typically via BAT-file-based infection chains. The reporting did not specify an exact date, but places this activity in the post-patch 2025 exploitation wave.

Russian state-linked groups expand use against Ukrainian targets

After the patch, multiple Russia-linked espionage groups including APT44, TEMP.Armageddon, Turla, and RomCom-linked UNC4895 were observed exploiting CVE-2025-8088. Their campaigns focused heavily on Ukrainian military and government entities, delivering malware such as STOCKSTAY and related loaders/backdoors.

ESET publicly discloses the WinRAR vulnerability

In early August 2025, ESET disclosed CVE-2025-8088 and described how malicious RAR archives could write files to arbitrary locations, including Startup folders, leading to code execution at user login. ESET also tied the flaw to in-the-wild exploitation by RomCom.

Jul 30, 202511mo ago

RARLAB patches CVE-2025-8088 in WinRAR 7.13

RARLAB released WinRAR 7.13, fixing CVE-2025-8088, on 2025-07-30. The update addressed the path traversal issue affecting WinRAR for Windows, but exploitation continued afterward as an n-day vulnerability.

Jul 18, 20251y ago

RomCom exploits WinRAR flaw as a zero-day

ESET observed the Russia-aligned RomCom group exploiting CVE-2025-8088 as a zero-day in mid-to-late July 2025, including delivery of SnipBot/NESTPACKER-related payloads via spear-phishing lures. Reports also indicate at least one other criminal group used the flaw around the same period.

Exploitation of CVE-2025-8088 begins in the wild

Google Threat Intelligence Group assessed that exploitation of the WinRAR path traversal flaw CVE-2025-8088 began as early as 2025-07-18. Early attacks used crafted RAR archives abusing Windows Alternate Data Streams and directory traversal to drop payloads, often into the Windows Startup folder for persistence.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

45 LINKEDOpen in app
Affected products
14 linked
WinrarWinrarWindowsVirustotalTelegram7-ZipDropbox7-ZipDropboxGmailGmailGmailChromeMicrosoft Office
Organizations
12 linked
WinRARBleepingComputerRapid7Tom's HardwareBI.ZONEEsetDropboxDark ReadingMicrosoft CorporationTelegramGoogleSecurity Affairs
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.