Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Russian Hackers Exploit WinRAR Flaw to Deploy Malware

Russian Hackers Exploit WinRAR Flaw to Deploy Malware

Posted on June 15, 2026 By CWS

In a worrying development, Russian hackers are exploiting a vulnerability in WinRAR to infiltrate Ukrainian organizations and steal sensitive data such as passwords and session cookies. This flaw, identified as CVE-2025-8088, was supposedly fixed in July 2025, yet remains a target for cyber attackers.

Persistent Exploitation of a Patched Vulnerability

Despite the availability of a patch, the vulnerability continues to be exploited by numerous Russian-aligned groups. Two prominent groups, SHADOW-EARTH-066 and Earth Dahu, are actively leveraging this flaw. SHADOW-EARTH-066, also known as UAC-0226, has been particularly focused on deploying an enhanced version of the GIFTEDCROOK malware.

Earth Dahu, recognized for its long-standing operations against Ukraine since 2013, has also been using this exploit. Both groups have been observed creating new exploit samples as recently as April 2026, indicating ongoing malicious activity.

Methods of Attack and Impact

According to a Trend Micro report shared with Cyber Security News, both groups utilize spear-phishing emails to deliver malicious RAR files exploiting CVE-2025-8088. Victims who open these files with outdated WinRAR versions unknowingly execute a payload that activates upon the next system login, dropping files into the Windows Startup folder without any alerts.

The SHADOW-EARTH-066 group has targeted Ukrainian military and government institutions, whereas Earth Dahu has used Cloudflare Workers to deploy espionage tools. Despite different approaches, both groups exploit the same vulnerability.

Challenges in Mitigating the Threat

Other Russian-linked actors, such as Sandworm and Turla, have also been exploiting this flaw. This ongoing threat highlights a significant security gap: WinRAR’s lack of automatic updates and standard enterprise patch channels, which allows outdated versions to remain operational unnoticed.

The vulnerability, rated CVSS 8.4, involves a path traversal flaw that permits attackers to write files outside the extraction directory using NTFS Alternate Data Streams. This process includes dropping an LNK shortcut, a PowerShell loader, and an encoded DLL into critical system locations.

SHADOW-EARTH-066’s attack chain leads to the theft of data, including passwords and session cookies, which are encrypted and sent to command-and-control servers. The malware cleans up afterward to minimize detection.

Recommendations for Organizations

Security experts advise immediate verification of WinRAR versions across all systems, recommending the upgrade to version 7.13 or later. It’s crucial to search for unusual LNK or HTA files in the Startup folder and monitor C:ProgramData for suspicious files. Organizations should also block known command-and-control IP addresses to prevent data exfiltration.

In cases of confirmed compromise, rotating saved credentials and enabling multi-factor authentication on critical accounts are essential steps to mitigate the impact. Security teams must remain vigilant to these evolving threats to enhance their cybersecurity defenses.

Cyber Security News Tags:CVE-2025-8088, cyber attack, Cybersecurity, GIFTEDCROOK, Malware, Russian hackers, security patch, spear-phishing, Trend Micro, Ukraine, Vulnerability, WinRAR

Post navigation

Previous Post: Maine Suspends Data Breach Portal Amid False Reports
Next Post: FBI and Google Dismantle Massive Phishing Network

Related Posts

RondoDox Botnet’s Expansive Exploit Arsenal and IP Tactics RondoDox Botnet’s Expansive Exploit Arsenal and IP Tactics Cyber Security News
Malicious npm Package with 206k Downloads Attacking GitHub-Owned Repositories to Exfiltrate Tokens Malicious npm Package with 206k Downloads Attacking GitHub-Owned Repositories to Exfiltrate Tokens Cyber Security News
CISA Alerts on Critical Ivanti EPMM Vulnerability CISA Alerts on Critical Ivanti EPMM Vulnerability Cyber Security News
Critical Veeam Backup RCE Vulnerabilities Let Attackers Execute Malicious Code Remotely Critical Veeam Backup RCE Vulnerabilities Let Attackers Execute Malicious Code Remotely Cyber Security News
Triple Combo – Kimsuky Hackers Attack Facebook, Email, and Telegram Users Triple Combo – Kimsuky Hackers Attack Facebook, Email, and Telegram Users Cyber Security News
17K+ SharePoint Servers Exposed to Internet 17K+ SharePoint Servers Exposed to Internet Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Casbaneiro Trojan Targets Latin American Banks
  • CISOs Tackle AI Risks While Balancing Innovation
  • GitHub Awards Record $100K for Major RCE Vulnerability
  • Telus Alerts Customers to Data Breach Incidents
  • Critical Patch Issued for ScreenConnect Vulnerability

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Casbaneiro Trojan Targets Latin American Banks
  • CISOs Tackle AI Risks While Balancing Innovation
  • GitHub Awards Record $100K for Major RCE Vulnerability
  • Telus Alerts Customers to Data Breach Incidents
  • Critical Patch Issued for ScreenConnect Vulnerability

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark