Attackers are exploiting CVE-2025-8088, a path traversal vulnerability affecting WinRAR versions earlier than 7.13, to gain initial access through malicious RAR archives delivered by spear-phishing. Crafted archives write payloads outside the intended extraction directory, potentially enabling arbitrary code execution through shortcuts or other launch mechanisms. Italy’s CSIRT reported active exploitation in August 2025, following RARLAB’s July 30 patch release, and noted that a public proof-of-concept exploit was available.
Threat Landscape subsequently reported multiple unnamed intrusion sets using the flaw to deploy Amaranth Loader, with follow-on tooling including the Havoc framework and a Telegram-controlled remote access trojan. The campaigns conceal payloads using Alternate Data Streams and employ HTTPS, commercial CDN fronting, geofencing, and short-lived domains to reduce exposure to scanning and sandbox analysis. Continued exploitation despite the available fix makes updating all vulnerable WinRAR installations to version 7.13 or later a priority; defenders should also investigate suspicious archive extraction, unexpected file writes, and shortcut-triggered execution.

See which actors are running it and whether you're in range.
4 events from the most recent confirmed update back to the earliest known activity.
RARLAB patched CVE-2025-8088 on July 30, 2025. The vulnerability affects WinRAR versions earlier than 7.13 and can enable arbitrary code execution when a specially crafted archive is extracted.
Multiple unnamed intrusion sets were observed exploiting CVE-2025-8088 through spear-phishing RAR attachments to deploy Amaranth Loader, with follow-on tooling including Havoc and a Telegram-controlled remote access trojan. The campaigns concealed payloads using Alternate Data Streams and used CDN-fronted, geofenced command-and-control infrastructure.
CSIRT Italia reported that a proof-of-concept exploit for CVE-2025-8088 was publicly available online.
CSIRT Italia reported that active exploitation of CVE-2025-8088 had been detected in the wild. The advisory recommended updating vulnerable WinRAR installations according to the vendor's security bulletin.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
3 references tracked. Mallory keeps watching after this page renders.
threatlandscape.io
Open sourceacn.gov.it
Open sourcecve.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.