Google Threat Intelligence Group (GTIG) reported ongoing, widening exploitation of a high-severity WinRAR path traversal flaw, CVE-2025-8088, roughly six months after it was disclosed and patched by RARLAB. GTIG assessed exploitation began as early as July 18, 2025 (including activity nearly two weeks before the vendor fix) and has expanded across a diverse set of adversaries, spanning Russia- and China-linked espionage actors as well as financially motivated cybercriminals. Reported targeting includes military, government, and technology organizations, with multiple Russia-aligned operations focusing on Ukrainian entities.
Technical reporting indicates the vulnerability abuses Windows Alternate Data Streams (ADS) within crafted archives to perform directory traversal and write files to arbitrary locations, including the Windows Startup folder for persistence. GTIG and other researchers describe exploit chains where a user opens a benign decoy (e.g., a PDF) while hidden ADS entries extract and drop executable content such as LNK, HTA, BAT, CMD, or script files that run at login; observed payloads include remote access trojans, infostealers, and malware frameworks used by named state actors (e.g., RomCom/UNC4895, APT44, TEMP.Armageddon, Turla) in addition to broader criminal activity across multiple regions.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
10 events from the most recent confirmed update back to the earliest known activity.
Alongside its reporting on CVE-2025-8088, Google warned in late January 2026 that another WinRAR flaw, CVE-2025-6218, was also facing exploitation attempts by multiple actors. This reinforced concerns about attackers' continued use of patched WinRAR vulnerabilities.
In late January 2026, Google Threat Intelligence Group published findings that CVE-2025-8088 was still being actively exploited roughly six months after patching by a mix of nation-state and financially motivated actors. Google also published indicators of compromise and urged organizations to update WinRAR and hunt for related activity.
An exploit supplier using the name 'zeroplayer' was reported advertising a WinRAR zero-day/exploit in 2025, with some reports citing a price of $80,000. Researchers assessed this exploit-supply activity helped multiple state and criminal actors obtain and operationalize the capability.
Multiple criminal groups began using CVE-2025-8088 to distribute commodity RATs, stealers, Telegram bot-controlled backdoors, and phishing tooling. Reported victim sectors and regions included hospitality, banking, Indonesia, South America, and LATAM, including campaigns targeting Brazilian banking users with a malicious Chrome extension.
Google linked a PRC-based threat actor to exploitation of CVE-2025-8088 to deploy PoisonIvy, typically via BAT-file-based infection chains. The reporting did not specify an exact date, but places this activity in the post-patch 2025 exploitation wave.
After the patch, multiple Russia-linked espionage groups including APT44, TEMP.Armageddon, Turla, and RomCom-linked UNC4895 were observed exploiting CVE-2025-8088. Their campaigns focused heavily on Ukrainian military and government entities, delivering malware such as STOCKSTAY and related loaders/backdoors.
In early August 2025, ESET disclosed CVE-2025-8088 and described how malicious RAR archives could write files to arbitrary locations, including Startup folders, leading to code execution at user login. ESET also tied the flaw to in-the-wild exploitation by RomCom.
RARLAB released WinRAR 7.13, fixing CVE-2025-8088, on 2025-07-30. The update addressed the path traversal issue affecting WinRAR for Windows, but exploitation continued afterward as an n-day vulnerability.
ESET observed the Russia-aligned RomCom group exploiting CVE-2025-8088 as a zero-day in mid-to-late July 2025, including delivery of SnipBot/NESTPACKER-related payloads via spear-phishing lures. Reports also indicate at least one other criminal group used the flaw around the same period.
Google Threat Intelligence Group assessed that exploitation of the WinRAR path traversal flaw CVE-2025-8088 began as early as 2025-07-18. Early attacks used crafted RAR archives abusing Windows Alternate Data Streams and directory traversal to drop payloads, often into the Windows Startup folder for persistence.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
12 references tracked. Mallory keeps watching after this page renders.
tomshardware.com
Open sourcesecurityaffairs.com
Open sourcethecyberexpress.com
Open sourcesecurityonline.info
Open sourcecybersecuritynews.com
Open sourcedarkreading.com
Open sourcecyberscoop.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.