ESET reported that the Russia-aligned RomCom group actively exploited the WinRAR zero-day CVE-2025-8088, a path traversal flaw involving Windows Alternate Data Streams that let malicious archives appear harmless while dropping files during extraction. The attacks used spearphishing emails with CV/resume-themed RAR attachments to target organizations in finance, manufacturing, defense, and logistics across Europe and Canada, and the exploitation chain deployed RomCom-associated tooling including a Mythic agent, a SnipBot variant, and RustyClaw/MeltingClaw downloaders. ESET said the flaw was fixed in WinRAR 7.13, warned that other actors also began exploiting it, and urged updates for WinRAR and downstream UnRAR.dll consumers.
Separate reporting from Trend Micro described 2025 intrusion campaigns tracked as SHADOW-VOID-042 that showed overlap with activity previously attributed to Void Rabisu/ROMCOM, though attribution remained unconfirmed. Those operations used tailored social-engineering lures aimed at executives and HR staff, and later impersonated Trend Micro browser security and Apex One updates against Trend Micro, a subsidiary, a partner, and other organizations. Recovered components showed a multi-stage chain using a Cloudflare-themed landing page, JavaScript exploiting CVE-2018-6065, delivery of an encrypted binary to C:\ProgramData\Microsoft\Windows\SystemProcessHost.exe, and persistence through a scheduled task running as SYSTEM; Trend Micro said early disruption prevented recovery of the final payload.

See which actors are running it and whether you're in range.
13 events from the most recent confirmed update back to the earliest known activity.
Trend Micro published research on two 2025 campaigns it tracks as SHADOW-VOID-042, noting overlaps with Void Rabisu/ROMCOM but saying attribution confidence was insufficient to merge them. The company said the final payload was not recovered and ROMCOM deployment could not be confirmed.
Trend Vision One quarantined most spear-phishing emails and blocked malicious landing pages in the November 2025 campaign, interrupting the infection chain before later-stage payload retrieval. Because of this early disruption, Trend Micro could not determine the final malware payload.
In November 2025, SHADOW-VOID-042 used Trend Micro-branded browser security and Apex One update lures against Trend Micro, its subsidiary, a partner, and organizations in other industries. The targets included executives and upper management in cybersecurity, energy, IT, and logistics.
In October 2025, the intrusion set Trend Micro tracks as SHADOW-VOID-042 used tailored social-engineering lures such as anonymous HR harassment complaints, research invitations, and questionnaires. The campaign targeted executives and HR personnel across multiple sectors.
ESET publicly reported that RomCom and another threat actor had exploited the WinRAR zero-day CVE-2025-8088, and said BI.ZONE had independently discovered the vulnerability. The report detailed the ADS-based path traversal technique and associated RomCom payload chains.
WinRAR 7.13 was published with a fix for CVE-2025-8088. ESET urged users and downstream consumers of UnRAR.dll and portable UnRAR source code to update.
ESET contacted WinRAR about CVE-2025-8088, and WinRAR fixed the issue the same day in WinRAR 7.13 beta 1. The patch addressed the zero-day affecting WinRAR and related Windows extraction components.
ESET researchers discovered a previously unknown WinRAR zero-day being exploited in the wild by RomCom. The flaw, later assigned CVE-2025-8088, is a path traversal issue involving Windows Alternate Data Streams.
From July 18 to July 21, 2025, ESET observed spearphishing campaigns targeting financial, manufacturing, defense, and logistics organizations in Europe and Canada using CV/resume lures and malicious RAR attachments. ESET said its telemetry did not show successful compromise of the observed targets.
ESET published research describing Mozilla and Windows zero-day and zero-click vulnerabilities exploited by the Russia-aligned RomCom group. The reference establishes a public disclosure by ESET of RomCom zero-day activity.
ESET cited RomCom's prior exploitation of CVE-2024-9680 chained with CVE-2024-49039 against Firefox, Thunderbird, and Tor Browser. This was noted as another major zero-day campaign preceding the WinRAR case.
ESET cited RomCom's prior in-the-wild exploitation of CVE-2023-36884 via Microsoft Word. This was presented as earlier evidence of the group's history of zero-day use.
Google patched Chrome vulnerability CVE-2018-6065 in version 65.0.3325.146. Trend Micro later found code exploiting this older flaw in recovered JavaScript from a 2025 intrusion chain.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 24 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
3 references tracked. Mallory keeps watching after this page renders.
trendaisecurity.com
Open sourcewelivesecurity.com
Open sourceeset.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.