Check Point Research[verified]@_CPResearch_Active Exploitation
Amaranth‑Dragon weaponized WinRAR CVE‑2025‑8088 to conduct targeted espionage in Southeast Asia, deploying custom loaders, a Telegram RAT, and geofenced C2.
Sekurak[verified]@SekurakActive Exploitation
Researchers report that the Amaranth‑Dragon group is actively exploiting WinRAR CVE‑2025‑8088 in a cyber‑espionage campaign targeting strategic assets.
780th Military Intelligence Brigade (Cyber)[verified]@780thCActive Exploitation
Russia-aligned campaigns are actively exploiting WinRAR’s CVE-2025-8088 against Ukraine, even a year after the flaw was patched.
780th Military Intelligence Brigade (Cyber)[verified]@780thCActive Exploitation
The post states that Gamaredon is actively exploiting CVE-2025-8088 against Ukrainian targets, but provides no details on patches or technical aspects.
Nextron Research ⚡️[verified]@nextronresearchActive Exploitation
The text reports that Gamaredon is actively exploiting CVE-2025-8088 (a WinRAR path‑traversal flaw) via malicious RAR archives to gain persistence on Ukrainian targets.
MalwareHunterTeam[verified]@malwrhunterteamGeneral
The tweet reports sightings of untagged archives linked to CVE-2025-8088 across multiple countries but does not provide evidence of active exploitation, exploit code, patches, or detailed vulnerability data.
780th Military Intelligence Brigade (Cyber)[verified]@780thCActive Exploitation
Check Point Research reports that Amaranth-Dragon, an APT-41 variant, is weaponizing CVE-2025-8088 for targeted espionage, suggesting active exploitation in the wild.
780th Military Intelligence Brigade (Cyber)[verified]@780thCActive Exploitation
Government-backed and financially motivated threat actors are actively exploiting WinRAR vulnerability CVE-2025-8088, which was discovered and patched in July 2025.