CVE-2025-8088Active Exploitation(dtsearch / dtsearch)

CRITICALCVSS 8.8 · HIGHCISA KEV

Exploitation observed; activity peaked at 84 mentions and remains active

Immediate actions

  • Patch dtsearch dtsearch systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

A path traversal vulnerability affecting the Windows version of WinRAR allows the attackers to execute arbitrary code by crafting malicious archive files. This vulnerability was exploited in the wild and was discovered by Anton Cherepanov, Peter Košinár, and Peter Strýček from ESET.

9.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2025-09-02. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-35

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • dtsearch
  • windows
  • winrar

Threat summary

  • Active exploitation appears in 289 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 375 mentions across 91 observed days

What's happening

  • Active exploitation reported across 289 signals
  • Exploit tool or code specified in 28 signals
  • PoC mentioned or linked in 42 signals
  • Patch or workaround mentioned in 107 signals
  • Technical details provided in 99 signals
  • General: 44 classified signals
  • Peaked 89d ago at 84 mentions (2026-01-28); latest day: 1
  • 375 total mentions across 91 days

Affected systems

Products
dtsearchwindowswinrar

1 version affected across 3 products

Deep dive

Activity timeline375 mentions / 91d
021426384Mentions · 2026-01-27: 9Mentions · 2026-01-28: 84Mentions · 2026-01-29: 36Mentions · 2026-01-30: 10Mentions · 2026-01-31: 5Mentions · 2026-02-02: 2Mentions · 2026-02-03: 1Mentions · 2026-02-04: 21Mentions · 2026-02-05: 23Mentions · 2026-02-06: 13Mentions · 2026-02-07: 2Mentions · 2026-02-08: 2Mentions · 2026-02-09: 6Mentions · 2026-02-10: 5Mentions · 2026-02-12: 2Mentions · 2026-02-14: 1Mentions · 2026-02-16: 2Mentions · 2026-02-17: 5Mentions · 2026-02-19: 1Mentions · 2026-02-21: 1Mentions · 2026-02-23: 1Mentions · 2026-02-26: 2Mentions · 2026-02-27: 1Mentions · 2026-03-02: 2Mentions · 2026-03-03: 1Mentions · 2026-03-04: 1Mentions · 2026-03-05: 1Mentions · 2026-03-07: 1Mentions · 2026-03-09: 1Mentions · 2026-03-10: 1Mentions · 2026-03-15: 1Mentions · 2026-03-16: 1Mentions · 2026-03-17: 1Mentions · 2026-03-18: 1Mentions · 2026-03-19: 2Mentions · 2026-03-20: 1Mentions · 2026-03-22: 1Mentions · 2026-03-27: 1Mentions · 2026-03-29: 2Mentions · 2026-03-31: 1Mentions · 2026-04-04: 2Mentions · 2026-04-05: 2Mentions · 2026-04-08: 2Mentions · 2026-04-09: 2Mentions · 2026-04-10: 1Mentions · 2026-04-13: 1Mentions · 2026-04-14: 1Mentions · 2026-04-15: 1Mentions · 2026-04-16: 1Mentions · 2026-04-20: 1Mentions · 2026-05-04: 2Mentions · 2026-05-13: 4Mentions · 2026-05-14: 1Mentions · 2026-05-18: 1Mentions · 2026-05-21: 1Mentions · 2026-05-23: 1Mentions · 2026-05-28: 1Mentions · 2026-06-02: 8Mentions · 2026-06-03: 5Mentions · 2026-06-04: 2Mentions · 2026-06-05: 1Mentions · 2026-06-08: 4Mentions · 2026-06-09: 13Mentions · 2026-06-10: 9Mentions · 2026-06-11: 9Mentions · 2026-06-12: 2Mentions · 2026-06-14: 3Mentions · 2026-06-15: 4Mentions · 2026-06-16: 2Mentions · 2026-06-17: 3Mentions · 2026-06-18: 2Mentions · 2026-06-19: 2Mentions · 2026-06-20: 1Mentions · 2026-06-21: 1Mentions · 2026-06-22: 1Mentions · 2026-06-23: 1Mentions · 2026-06-24: 1Mentions · 2026-06-25: 2Mentions · 2026-06-26: 1Mentions · 2026-06-27: 3Mentions · 2026-06-29: 3Mentions · 2026-07-03: 1Mentions · 2026-07-10: 1Mentions · 2026-07-21: 2Mentions · 2026-07-22: 1Mentions · 2026-07-27: 1Mentions · 2026-08-07: 2Mentions · 2026-09-24: 1Mentions · 2026-09-30: 1Mentions · 2026-10-05: 1Mentions · 2026-10-07: 1PoC Mentioned / Linked · 2026-01-27: 1PoC Mentioned / Linked · 2026-01-28: 1PoC Mentioned / Linked · 2026-02-03: 1PoC Mentioned / Linked · 2026-02-06: 2PoC Mentioned / Linked · 2026-02-09: 1PoC Mentioned / Linked · 2026-02-10: 1PoC Mentioned / Linked · 2026-02-14: 1PoC Mentioned / Linked · 2026-02-17: 2PoC Mentioned / Linked · 2026-02-23: 1PoC Mentioned / Linked · 2026-02-26: 1PoC Mentioned / Linked · 2026-03-02: 2PoC Mentioned / Linked · 2026-03-05: 1PoC Mentioned / Linked · 2026-03-09: 1PoC Mentioned / Linked · 2026-03-10: 1PoC Mentioned / Linked · 2026-03-16: 1PoC Mentioned / Linked · 2026-03-19: 2PoC Mentioned / Linked · 2026-03-31: 1PoC Mentioned / Linked · 2026-04-04: 2PoC Mentioned / Linked · 2026-04-05: 1PoC Mentioned / Linked · 2026-04-09: 1PoC Mentioned / Linked · 2026-04-13: 1PoC Mentioned / Linked · 2026-04-14: 1PoC Mentioned / Linked · 2026-04-15: 1PoC Mentioned / Linked · 2026-05-04: 1PoC Mentioned / Linked · 2026-05-18: 1PoC Mentioned / Linked · 2026-05-28: 1PoC Mentioned / Linked · 2026-06-09: 2PoC Mentioned / Linked · 2026-06-10: 1PoC Mentioned / Linked · 2026-06-11: 1PoC Mentioned / Linked · 2026-06-14: 1PoC Mentioned / Linked · 2026-06-17: 2PoC Mentioned / Linked · 2026-06-18: 1PoC Mentioned / Linked · 2026-06-23: 1PoC Mentioned / Linked · 2026-06-25: 1PoC Mentioned / Linked · 2026-07-10: 1Exploit Tool / Code · 2026-02-04: 3Exploit Tool / Code · 2026-02-05: 3Exploit Tool / Code · 2026-02-06: 1Exploit Tool / Code · 2026-02-17: 2Exploit Tool / Code · 2026-02-23: 1Exploit Tool / Code · 2026-03-09: 1Exploit Tool / Code · 2026-03-10: 1Exploit Tool / Code · 2026-03-16: 1Exploit Tool / Code · 2026-03-19: 1Exploit Tool / Code · 2026-03-31: 1Exploit Tool / Code · 2026-04-04: 2Exploit Tool / Code · 2026-04-13: 1Exploit Tool / Code · 2026-04-14: 1Exploit Tool / Code · 2026-04-15: 1Exploit Tool / Code · 2026-06-03: 1Exploit Tool / Code · 2026-06-09: 3Exploit Tool / Code · 2026-06-10: 1Exploit Tool / Code · 2026-06-17: 1Exploit Tool / Code · 2026-06-23: 1Exploit Tool / Code · 2026-06-25: 1Active Exploitation · 2026-01-27: 8Active Exploitation · 2026-01-28: 75Active Exploitation · 2026-01-29: 30Active Exploitation · 2026-01-30: 7Active Exploitation · 2026-01-31: 5Active Exploitation · 2026-02-04: 18Active Exploitation · 2026-02-05: 22Active Exploitation · 2026-02-06: 9Active Exploitation · 2026-02-07: 2Active Exploitation · 2026-02-08: 1Active Exploitation · 2026-02-09: 3Active Exploitation · 2026-02-10: 3Active Exploitation · 2026-02-12: 2Active Exploitation · 2026-02-14: 1Active Exploitation · 2026-02-17: 1Active Exploitation · 2026-02-19: 1Active Exploitation · 2026-02-21: 1Active Exploitation · 2026-02-23: 1Active Exploitation · 2026-02-26: 1Active Exploitation · 2026-02-27: 1Active Exploitation · 2026-03-02: 1Active Exploitation · 2026-03-03: 1Active Exploitation · 2026-03-04: 1Active Exploitation · 2026-03-07: 1Active Exploitation · 2026-03-09: 1Active Exploitation · 2026-03-10: 1Active Exploitation · 2026-03-16: 1Active Exploitation · 2026-03-20: 1Active Exploitation · 2026-03-22: 1Active Exploitation · 2026-03-27: 1Active Exploitation · 2026-03-29: 1Active Exploitation · 2026-04-04: 1Active Exploitation · 2026-04-05: 1Active Exploitation · 2026-04-08: 1Active Exploitation · 2026-04-09: 1Active Exploitation · 2026-05-04: 1Active Exploitation · 2026-05-13: 3Active Exploitation · 2026-05-18: 1Active Exploitation · 2026-06-02: 7Active Exploitation · 2026-06-03: 5Active Exploitation · 2026-06-04: 2Active Exploitation · 2026-06-08: 4Active Exploitation · 2026-06-09: 12Active Exploitation · 2026-06-10: 9Active Exploitation · 2026-06-11: 6Active Exploitation · 2026-06-12: 2Active Exploitation · 2026-06-14: 1Active Exploitation · 2026-06-15: 4Active Exploitation · 2026-06-16: 2Active Exploitation · 2026-06-17: 2Active Exploitation · 2026-06-18: 2Active Exploitation · 2026-06-19: 2Active Exploitation · 2026-06-20: 1Active Exploitation · 2026-06-22: 1Active Exploitation · 2026-06-24: 1Active Exploitation · 2026-06-25: 1Active Exploitation · 2026-06-26: 1Active Exploitation · 2026-06-27: 3Active Exploitation · 2026-06-29: 3Active Exploitation · 2026-07-03: 1Active Exploitation · 2026-07-10: 1Active Exploitation · 2026-07-22: 1Active Exploitation · 2026-08-07: 2Active Exploitation · 2026-09-24: 1Patch / Workaround · 2026-01-27: 2Patch / Workaround · 2026-01-28: 31Patch / Workaround · 2026-01-29: 18Patch / Workaround · 2026-01-30: 5Patch / Workaround · 2026-01-31: 3Patch / Workaround · 2026-02-04: 3Patch / Workaround · 2026-02-05: 3Patch / Workaround · 2026-02-06: 1Patch / Workaround · 2026-02-09: 1Patch / Workaround · 2026-02-12: 1Patch / Workaround · 2026-02-19: 1Patch / Workaround · 2026-03-27: 1Patch / Workaround · 2026-03-29: 2Patch / Workaround · 2026-05-04: 1Patch / Workaround · 2026-06-02: 2Patch / Workaround · 2026-06-08: 1Patch / Workaround · 2026-06-09: 6Patch / Workaround · 2026-06-10: 7Patch / Workaround · 2026-06-11: 5Patch / Workaround · 2026-06-12: 1Patch / Workaround · 2026-06-14: 1Patch / Workaround · 2026-06-15: 3Patch / Workaround · 2026-06-17: 2Patch / Workaround · 2026-06-18: 1Patch / Workaround · 2026-06-19: 1Patch / Workaround · 2026-06-20: 1Patch / Workaround · 2026-06-22: 1Patch / Workaround · 2026-06-29: 1Patch / Workaround · 2026-07-03: 1Technical Details · 2026-01-27: 3Technical Details · 2026-01-28: 20Technical Details · 2026-01-29: 6Technical Details · 2026-01-30: 6Technical Details · 2026-01-31: 2Technical Details · 2026-02-02: 1Technical Details · 2026-02-04: 7Technical Details · 2026-02-05: 12Technical Details · 2026-02-06: 2Technical Details · 2026-02-08: 1Technical Details · 2026-02-09: 1Technical Details · 2026-02-10: 1Technical Details · 2026-02-12: 2Technical Details · 2026-02-17: 3Technical Details · 2026-02-19: 1Technical Details · 2026-03-19: 1Technical Details · 2026-03-29: 1Technical Details · 2026-03-31: 1Technical Details · 2026-04-05: 1Technical Details · 2026-04-08: 1Technical Details · 2026-04-10: 1Technical Details · 2026-04-20: 1Technical Details · 2026-05-13: 1Technical Details · 2026-05-14: 1Technical Details · 2026-05-21: 1Technical Details · 2026-06-02: 2Technical Details · 2026-06-03: 2Technical Details · 2026-06-04: 1Technical Details · 2026-06-09: 4Technical Details · 2026-06-10: 3Technical Details · 2026-06-12: 1Technical Details · 2026-06-15: 2Technical Details · 2026-06-18: 1Technical Details · 2026-06-19: 1Technical Details · 2026-06-22: 1Technical Details · 2026-06-26: 1Technical Details · 2026-07-03: 1Technical Details · 2026-09-24: 101-2702-0602-1903-0703-2204-1305-2106-1006-2007-0310-07
Signal classification7 categories
Active Exploitation
28376.1%
General
4411.8%
Exploit
133.5%
PoC
113.0%
Patch
102.7%
Disclosure
92.4%
Referenced assets274 URLs
By indicator
Classification over time
DateTotalLabels
2026-01-279
Active Exploitation8General1
2026-01-2884
Active Exploitation74Exploit1General6Patch3
2026-01-2936
Active Exploitation30Disclosure1False Positive1General2Patch2
2026-01-3010
Active Exploitation7Disclosure1General1Patch1
2026-01-315
Active Exploitation5
2026-02-022
Disclosure1General1
2026-02-031
PoC1
2026-02-0421
Active Exploitation18Disclosure1General2
2026-02-0523
Active Exploitation22General1
2026-02-0613
Active Exploitation9Disclosure1General3
2026-02-072
Active Exploitation2
2026-02-082
Active Exploitation1False Positive1
2026-02-096
Active Exploitation2General3Patch1
2026-02-105
Active Exploitation3General1PoC1
2026-02-122
Active Exploitation2
2026-02-141
Active Exploitation1
2026-02-162
General2
2026-02-175
Active Exploitation1Disclosure1Exploit1General1PoC1
2026-02-191
Active Exploitation1
2026-02-211
Active Exploitation1
2026-02-231
Active Exploitation1
2026-02-262
Active Exploitation1General1
2026-02-271
Active Exploitation1
2026-03-022
Active Exploitation1PoC1
2026-03-031
Active Exploitation1
2026-03-041
Active Exploitation1
2026-03-051
Exploit1
2026-03-071
Active Exploitation1
2026-03-091
Active Exploitation1
2026-03-101
Exploit1
2026-03-151
General1
2026-03-161
Active Exploitation1
2026-03-171
General1
2026-03-181
General1
2026-03-192
Exploit1PoC1
2026-03-201
Active Exploitation1
2026-03-221
Active Exploitation1
2026-03-271
Active Exploitation1
2026-03-292
Active Exploitation1Patch1
2026-03-311
PoC1
2026-04-042
Active Exploitation1PoC1
2026-04-052
Active Exploitation1General1
2026-04-082
Active Exploitation1General1
2026-04-092
Active Exploitation1General1
2026-04-101
General1
2026-04-131
Exploit1
2026-04-141
Exploit1
2026-04-151
Exploit1
2026-04-161
Exploit1
2026-04-201
General1
2026-05-042
Patch1PoC1
2026-05-134
Active Exploitation3General1
2026-05-141
General1
2026-05-181
Active Exploitation1
2026-05-211
Disclosure1
2026-05-231
Disclosure1
2026-05-281
PoC1
2026-06-028
Active Exploitation7Patch1
2026-06-035
Active Exploitation4Exploit1
2026-06-042
Active Exploitation2
2026-06-051
General1
2026-06-084
Active Exploitation4
2026-06-0913
Active Exploitation12General1
2026-06-109
Active Exploitation9
2026-06-119
Active Exploitation6General2PoC1
2026-06-122
Active Exploitation2
2026-06-143
Active Exploitation1General1PoC1
2026-06-154
Active Exploitation4
2026-06-162
Active Exploitation2
2026-06-173
Active Exploitation2Exploit1
2026-06-182
Active Exploitation2
2026-06-192
Active Exploitation2
2026-06-201
Active Exploitation1
2026-06-211
General1
2026-06-221
Active Exploitation1
2026-06-231
Exploit1
2026-06-241
Active Exploitation1
2026-06-252
Exploit1General1
2026-06-261
Active Exploitation1
2026-06-273
Active Exploitation3
2026-06-293
Active Exploitation3
2026-07-031
Active Exploitation1
2026-07-101
Active Exploitation1
2026-07-212
General2
2026-07-221
Active Exploitation1
2026-07-271
Disclosure1
2026-08-072
Active Exploitation2
2026-09-241
Active Exploitation1
Full discourse20 posts
  • Mandiant (part of Google Cloud)@Mandiant
    Active Exploitation

    We are tracking widespread exploitation of critical WinRAR vulnerability CVE-2025-8088 by state-sponsored espionage groups and financially motivated actors. 🔍 All orgs and users should update to the latest version of WinRAR. Learn more and get IOCs: https://bit.ly/4t2FuAB https://t.co/LhSAAdnoHU

    Post summary

    CVE‑2025‑8088 is being widely exploited by state‑sponsored espionage groups and financially motivated actors. Users are urged to update WinRAR and obtain IOCs via the provided links.

    25551797121.1K
    127.7K followersView on X
  • Hedge Fund Manager@rich_hedge_fund
    Patch

    WinRAR evidently has a CVE-2025-8088 exploit. I suggest 7-zip which open source so it is safe.

    Post summary

    The post claims WinRAR has CVE‑2025‑8088 and recommends using 7‑zip as a safe workaround to avoid the vulnerability.

    3101117424105.7K
    191 followersView on X
  • Check Point Research@_CPResearch_
    Active Exploitation

    In 2025, Amaranth-Dragon APT weaponized the popular WinRAR CVE-2025-8088 for targeted espionage across Southeast Asia. Custom loader, Telegram RAT, geofenced C2, and event-themed lures. https://research.checkpoint.com/2026/amaranth-dragon-weaponizes-cve-2025-8088-for-targeted-espionage/

    Post summary

    Amaranth‑Dragon weaponized WinRAR CVE‑2025‑8088 to conduct targeted espionage in Southeast Asia, deploying custom loaders, a Telegram RAT, and geofenced C2.

    14071255316.2K
    24.6K followersView on X
  • The Hacker News@TheHackersNews
    Active Exploitation

    🇨🇳 China-linked Amaranth-Dragon targeted Southeast Asian government and law enforcement networks in 2025, with links to the APT41 ecosystem. Campaigns leveraged political lures and the WinRAR CVE-2025-8088 RCE flaw, using cloud delivery and geo-fenced infrastructure for stealth. 🔗 Read → https://thehackernews.com/2026/02/china-linked-amaranth-dragon-exploits.html

    Post summary

    The article reports that China-linked Amaranth-Dragon actively exploited the WinRAR CVE-2025-8088 RCE flaw against Southeast Asian government and law enforcement networks.

    3280691310.4K
    1.0M followersView on X
  • The Hacker News@TheHackersNews
    Active Exploitation

    🛑 A WinRAR bug fixed in July 2025 is still being exploited. Researchers at Google ties CVE-2025-8088 to Russia- and China-linked actors, plus cybercrime groups deploying RATs and stealers, showing how quickly n-days get reused. 🔗 Read → https://thehackernews.com/2026/01/google-warns-of-active-exploitation-of.html

    Post summary

    CVE‑2025‑8088, a WinRAR vulnerability fixed in July 2025, remains in active exploitation by state‑linked actors and cybercrime groups, illustrating rapid n‑day reuse.

    13706968.2K
    1.0M followersView on X
  • Sekurak@Sekurak
    Active Exploitation

    🚨 Nowa grupa Amaranth-Dragon (prawdopodobnie powiązana z chińskim wywiadem) atakuje strategiczne cele 🕵️‍♂️ Badacze bezpieczeństwa z Checkpoint Research wykryli nową kampanię cyberszpiegowską, wykorzystującą lukę w WinRAR (CVE-2025-8088) 🎯 Jak wygląda schemat ataku? Phishing ze złośliwym archiwum RAR – pierwsza faza. Wykorzystanie luki w WinRAR – skryte wypakowanie złośliwego skryptu do folderu Autostart. Nawiązanie połączenia z serwerem C2 w celu pobrania ładunku oraz klucza deszyfrującego payload. 🐉 Efektem końcowym jest przejęcie infrastruktury celu – malware Havoc C2 lub TGAmaranth RAT 🌍 Co ciekawe, serwer C2 przesyła dane, jeżeli adres IP pochodzi z konkretnego regionu geograficznego 👉 Szczegóły kampanii: https://sekurak.pl/nowa-kampania-cyberszpiegowska-grupa-amaranth-dragon-atakuje-strategiczne-cele-przy-uzyciu-luki-w-winrar-cve-2025-8088/

    Post summary

    Researchers report that the Amaranth‑Dragon group is actively exploiting WinRAR CVE‑2025‑8088 in a cyber‑espionage campaign targeting strategic assets.

    57069108.4K
    42.1K followersView on X
  • The Hacker News@TheHackersNews
    Active Exploitation

    🚨 Google has linked Turla to a new .NET backdoor. STOCKSTAY was used in espionage campaigns targeting #Ukraine government and military organizations. It overlaps with Kazuar and reached targets through phishing, RDP files, MSI installers, and #WinRAR CVE-2025-8088 lures. See the full attack details 🠖 https://thehackernews.com/2026/06/google-details-turlas-new-stockstay.html

    Post summary

    The statement reports that Google linked Turla’s new .NET backdoor, STOCKSTAY, to espionage activities with evidence of active exploitation, specifically using WinRAR CVE-2025‑8088 for lures, but it offers no PoC, tool details, or patch information.

    117149718.5K
    2.2M followersView on X
  • ⛃@fdgjaskldf30286
    General

    @vxunderground @DitherDude pretty sure it's CVE-2025-8088

    Post summary

    The tweet merely references the CVE identifier CVE-2025-8088 without providing additional context or details.

    2006363.2K
    3 followersView on X
  • ∆ndr 🍐@andres_html
    General

    @zabrakin @Pirat_Nation Actually it did with CVE-2025-8088

    Post summary

    The message references CVE-2025-8088 but provides no further context, evidence of exploitation, or technical detail.

    0006031.7K
    89 followersView on X
  • 780th Military Intelligence Brigade (Cyber)@780thC
    Active Exploitation

    Two separate Russia-aligned campaigns are still exploiting the WinRAR flaw CVE-2025-8088 against Ukrainian organizations nearly a year after it was patched Trend Micro https://www.trendmicro.com/en_us/research/26/f/old-winrar-flaw-fuels-attacks-on-ukraine.html @trendaisecurity

    Post summary

    Russia-aligned campaigns are actively exploiting WinRAR’s CVE-2025-8088 against Ukraine, even a year after the flaw was patched.

    01603983.8K
    35.4K followersView on X
  • 2ero@2eroHunter
    Active Exploitation

    #Bitter #APT also uses CVE-2025-8088. f6f2fdc38cd61d8d9e8cd35244585967 84128d40db28e8ee16215877d4c4b64a 41fcaf0267134fcdea7e4d516b69e16e https://cloud.google.com/blog/topics/threat-intelligence/exploiting-critical-winrar-vulnerability

    Post summary

    The tweet reports that the Bitter APT group reportedly exploits CVE‑2025‑8088; no PoC, exploit code, patch, or technical details are provided.

    011040122.7K
    3.4K followersView on X
  • The Hacker News@TheHackersNews
    Active Exploitation

    ⚠️ Gamaredon ran 35 phishing campaigns against Ukraine in 2025. ESET says it used new PowerShell tools, HTML smuggling, and CVE-2025-8088 to plant malware in Startup. Simple malware. Harder infrastructure. Read more ↓ https://thehackernews.com/2026/06/gamaredon-expands-ukraine-attacks-with.html https://t.co/yaaLfAdo16

    Post summary

    Gamaredon is actively exploiting CVE‑2025‑8088 in phishing campaigns against Ukraine, with new PowerShell tools aiding delivery.

    06041216.9K
    2.3M followersView on X
  • 780th Military Intelligence Brigade (Cyber)@780thC
    Active Exploitation

    Gamaredon, also known as Aqua Blizzard, Primitive Bear, Shuckworm or UAC-0010, has been exploiting CVE-2025-8088 to target Ukrainian organizations. Harfang Lab https://harfanglab.io/insidethelab/gamaredon-gammadrop-gammaload/ @harfanglab

    Post summary

    The post states that Gamaredon is actively exploiting CVE-2025-8088 against Ukrainian targets, but provides no details on patches or technical aspects.

    01303062.6K
    35.5K followersView on X
  • Nextron Research ⚡️@nextronresearch
    Active Exploitation

    We analyzed a #Gamaredon campaign targeting Ukraine that weaponizes CVE-2025-8088, the WinRAR path-traversal flaw, to gain persistence the moment a victim extracts the archive The activity has been running since February 2026 and is still ongoing, with the most recent samples seen in June 2026. Steady stream of military and conscription themed lures over four-plus months. The lures are #Ukrainian military and conscription documents (Відомість про самовільне залишення військової частини..., Повідомлення...) packed as .rar. The victim sees only a PDF name The trick is in the archive itself. A malicious NTFS alternate data stream carries a path-traversal sequence (..\..\..\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\) so that extracting the RAR silently plants a .lnk straight into the user's Startup folder. No user action beyond unpacking On next logon the shortcut runs a hidden PowerShell stager (abbreviated parameters, window hidden) with anti-analysis behavior: debugger and disk-space checks plus long sleeps to stall sandboxes before reaching out for the next stage THOR / Valhalla YARA hits: https://valhalla.nextron-systems.com/info/rule/SUSP_LNK_ScriptContent_Apr21_1 https://valhalla.nextron-systems.com/info/rule/SUSP_SCRIPT_PowerShell_Param_Abbrev_Jul21 https://github.com/Neo23x0/signature-base/search?q=SUSP_RAR_NTFS_ADS https://github.com/Neo23x0/signature-base/search?q=SUSP_LNK_SuspiciousCommands IOCs (SHA-256): 0a9bc91e7ea2c3931f662eea37c00c7c26c8996b65f6f7afe6cce8f6114f94b6 39dd1bd3bccc314d8933e5c41ed2ab084e4e20af569f77b7cf09abc5855b9483 1ebbdf3671cd5ca25a8a8e7ca2f6e46dd22c631e01bfcc5c909ae2fd680bf458 f668bd551859007cf2cc2a62bf0bf5414870a04e9782590c9bf85c849ddb308b 1c170b7470d507378ddb78e9d66305f1184e965baaf2d27ededb23a318a58953 bf338d88f60c0d352cd0d1b5e4bc6a1d9f1ac8fe1df48516ec0042cafda821e9 507b2fcdae058cebbd550965b90c44e878d7a2463058c846eeb68f0dc1b48eda f9d2907d6b1de3078a0f111cc98764a92baf5ebd06cc8ab02637a65eff3b7f3a

    Post summary

    The text reports that Gamaredon is actively exploiting CVE-2025-8088 (a WinRAR path‑traversal flaw) via malicious RAR archives to gain persistence on Ukrainian targets.

    01002983.4K
    3.7K followersView on X
  • R3BELF0X@goldenjackel12
    General

    #APT #Gamaredon Відомость про самовільне залишення військової частини 3018-4908.rar a113090d748d0dac7d488c97f1305af2 Повідомлення 4908-451.rar 473c65b922d3308a98c6b76c7d99a196 uploaded from #UKRAINE #exploit CVE-2025-8088 @smica83 @polygonben @IdaNotPro https://t.co/9wNmwp61tu

    Post summary

    The tweet merely states the presence of CVE-2025-8088 and includes a link, but provides no technical, exploit, or patch details. It appears to be a generic mention with no actionable information.

    0812986.4K
    288 followersView on X
  • MalwareHunterTeam@malwrhunterteam
    General

    Looks no one noticed it yet, so: in recent weeks, some strange CVE-2025-8088 exploiting archives were seen from different countries. Normally, when a CVE-2025-8088 exploiting archive gets uploaded to VT, there are detections from vendors mentioning the exploiting in some way and also VT itself adds a CVE tag to the file. From all of these - somehow crafted/modified/corrupted archives - I seen, 0 had any CVE/exploit detection from vendors on VT and 0 had the CVE tag. Some of these files not even got the rar tag on VT, with "File type: unknown", "Magic: data" in the properties list, only Magika detected as "RAR_ARCHIVE". Of course, already shared the samples with @smica83 for uploading to Bazaar, also shared with @jiriatvirlab and @marsomx_ for possible interest, but guess others could be interested too, so thought tweet about it... 🤷‍♂️

    Post summary

    The tweet reports sightings of untagged archives linked to CVE-2025-8088 across multiple countries but does not provide evidence of active exploitation, exploit code, patches, or detailed vulnerability data.

    14030108.8K
    255.7K followersView on X
  • 780th Military Intelligence Brigade (Cyber)@780thC
    Active Exploitation

    Check Point Research (CPR) has been tracking Amaranth-Dragon, a nexus of APT-41, previously aligned with Chinese interests. https://research.checkpoint.com/2026/amaranth-dragon-weaponizes-cve-2025-8088-for-targeted-espionage/ @_CPResearch_

    Post summary

    Check Point Research reports that Amaranth-Dragon, an APT-41 variant, is weaponizing CVE-2025-8088 for targeted espionage, suggesting active exploitation in the wild.

    01013011.9K
    34.4K followersView on X
  • Virus Bulletin@virusbtn
    Active Exploitation

    Google’s Threat Intelligence Group warns WinRAR CVE-2025-8088 is being exploited for initial access & payload delivery by both state-backed & financially motivated actors. The exploitation method allows files to be dropped into the Windows Startup folder. https://cloud.google.com/blog/topics/threat-intelligence/exploiting-critical-winrar-vulnerability https://t.co/Y0uuElibwt

    Post summary

    Google's Threat Intelligence Group reports that WinRAR CVE-2025-8088 is actively exploited by multiple threat actors to drop files into the Windows Startup folder for initial access and payload delivery.

    0513241.9K
    60.8K followersView on X
  • 780th Military Intelligence Brigade (Cyber)@780thC
    Active Exploitation

    Diverse Threat Actors Exploiting Critical WinRAR Vulnerability CVE-2025-8088 Google Threat Intelligence Group Discovered and patched in July 2025, government-backed threat actors linked to Russia and China as well as financially motivated threat actors continue to exploit this n-day across disparate operations. https://cloud.google.com/blog/topics/threat-intelligence/exploiting-critical-winrar-vulnerability @googlecloud

    Post summary

    Government-backed and financially motivated threat actors are actively exploiting WinRAR vulnerability CVE-2025-8088, which was discovered and patched in July 2025.

    01312611.3K
    34.4K followersView on X
  • Nicolas Krassas@Dinosn
    Active Exploitation

    Russian APTs Still Exploiting Patched WinRAR Flaw CVE-2025-8088 https://securityaffairs.com/193476/apt/russian-apts-still-exploiting-patched-winrar-flaw-cve-2025-8088.html

    Post summary

    Russian APT actors are continuing to exploit the now‑patched WinRAR vulnerability CVE‑2025‑8088, demonstrating active exploitation despite vendor remediation.

    04025111.8K
    158.9K followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
Appdtsearchdtsearch---
OSmicrosoftwindows---
Apprarlabwinrar---

Explore more