BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Russian Hackers Exploit Old WinRAR Flaw Against Ukraine

Unpatched WinRAR flaw exploited by Russian hackers to steal data from Ukrainian targets.

  • Two Russian-aligned hacking groups continue to exploit a patched WinRAR vulnerability to target Ukrainian organizations.
  • The flaw, CVE-2025-8088, allows attackers to hide malicious payloads outside the intended extraction directory.
  • The campaigns deliver information-stealing malware like GIFTEDCROOK and GammaSteel, stealing passwords, cookies, and documents.
  • The threat actors have adapted their methods, shifting away from Telegram for data exfiltration after Russia blocked the platform.
  • Analysts say the widespread use of WinRAR in Ukraine makes it a highly attractive target for ongoing cyber espionage.

Two Russia-aligned cyber attack campaigns, Earth Dahu and SHADOW-EARTH-066, are actively exploiting a known WinRAR flaw to compromise Ukrainian organizations, nearly a year after a patch was released. According to researchers, the activity demonstrates how unmanaged software leaves an entry point open long after a fix ships.

- Advertisement -

The vulnerability, CVE-2025-8088, is a path traversal flaw that allows attackers to write files outside the extraction directory. Trend Micro researchers Hiroyuki Kakara and Feike Hacquebord detailed the continued exploitation in an analysis published Monday. Consequently, this provides a stealthy method for delivering malicious payloads.

In one campaign, SHADOW-EARTH-066 now uses crafted RAR archives containing hidden payloads instead of Excel macro droppers. This new infection chain ultimately deploys an updated version of the GIFTEDCROOK information stealer. The malware targets browser passwords and cookies, then exfiltrates stolen documents before deleting all traces.

A notable shift involves the malware’s communication channel moving away from Telegram. This key modification likely aligns with Russia’s blocking of the messaging platform earlier this year. Meanwhile, the second group, Earth Dahu, has incorporated this WinRAR flaw into its arsenal since at least September 2025.

Earth Dahu’s attack chain leads to the deployment of GammaPhish and GammaLoad scripts. As recently documented by Sekoia, these are used to deploy GammaSteel, a comprehensive information stealer capable of monitoring file changes in real-time. The group is known for its industrial-scale effort to maintain long-term access.

- Advertisement -

The convergence of multiple state-backed groups on this single vulnerability highlights the scale of cyber threats facing Ukraine. Trend Micro noted that WinRAR’s deep integration into daily operations makes it a particularly attractive target for such espionage campaigns.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Oracle E-Business Flaw Actively Exploited

A critical flaw in Oracle Payments (CVE-2026-46817) is being actively exploited to take over...

Tommy Robinson’s son behind his ‘patriotic’ crypto token

British activist Tommy Robinson shilled his son's "Patriotic Bull" cryptocurrency token on X before...

AI Browser Extension Intercepted User Searches

A malicious Chrome extension impersonating the AI search engine Perplexity intercepted and logged user...

Saylor’s MicroStrategy to Sell Bitcoin Amid Crypto Slump

Strategy announced a new program authorizing the sale of up to $1.25 billion worth...

$3.7B in Stablecoins Frozen by Censorship

Tether and Circle have frozen approximately $3.7 billion in stablecoins on the Ethereum and...

Must Read

What Is a Sim Swap Hack?

You've likely heard the term 'sim-swap,' but do you really know what it means? It's a type of fraud that's rapidly increasing, where scammers...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading