Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Cyber Attacks Exploit WinRAR Flaw Against Ukraine

Cyber Attacks Exploit WinRAR Flaw Against Ukraine

Posted on June 9, 2026 By CWS

Two cyber campaigns linked to Russia are actively exploiting a vulnerability in WinRAR to attack Ukrainian organizations. These attacks persist despite the release of patches nearly a year ago. The flaw, identified as CVE-2025-8088, allows attackers to execute path traversal attacks through NTFS Alternate Data Streams, enabling file writes outside the intended extraction directory.

Exploitation by Notorious Groups

Trend Micro attributes this malicious activity to the groups Earth Dahu and SHADOW-EARTH-066. SHADOW-EARTH-066 has shifted from using Excel macro droppers to deploying crafted RAR archives with decoy PDFs and hidden payloads. These payloads include a Windows Shortcut file in the Startup folder, which triggers a PowerShell loader to execute an updated version of the information stealer, GIFTEDCROOK.

The malware targets sensitive data such as passwords and cookies from popular browsers like Google Chrome and Mozilla Firefox. Once the information is exfiltrated, all traces of the malware are removed to evade detection.

Strategic Shifts in Cyber Tactics

Significantly, the attackers have moved from using Telegram for data exfiltration to employing dedicated command-and-control servers. This change likely follows Russia’s ban on Telegram earlier in the year. The second group, Earth Dahu, has been leveraging the same WinRAR flaw since September 2025, utilizing an HTA-to-VBScript infection chain to deploy espionage tools.

Earth Dahu’s operations are characterized by their industrial-scale efforts to sustain access to compromised networks. The group employs GammaPhish, an HTML Application, to download and execute additional malicious components like GammaLoad and GammaSteel, which facilitate long-term data theft.

Implications for Ukraine’s Cybersecurity

WinRAR is a critical tool in many Ukrainian organizations, making it a prime target for cyber exploitation. The convergence of multiple state-backed actors on this single vulnerability underscores the significant cyber threats facing Ukraine. As these attacks continue, they highlight the urgent need for improved cybersecurity measures and awareness of software vulnerabilities.

In response to these threats, organizations are advised to update software promptly and implement robust security protocols to mitigate vulnerabilities. The ongoing cyber conflict emphasizes the importance of staying vigilant against evolving tactics employed by advanced persistent threats.

The Hacker News Tags:CVE-2025-8088, cyber attacks, cyber espionage, Cybersecurity, Earth Dahu, information stealer, SHADOW-EARTH-066, Trend Micro, Ukraine, WinRAR

Post navigation

Previous Post: Phishing Scams Exploit AI Tool Brands for Credential Theft

Related Posts

LOTUSLITE Backdoor Targets U.S. Policy Entities Using Venezuela-Themed Spear Phishing LOTUSLITE Backdoor Targets U.S. Policy Entities Using Venezuela-Themed Spear Phishing The Hacker News
CISA Flags TP-Link Router Flaws CVE-2023-50224 and CVE-2025-9377 as Actively Exploited CISA Flags TP-Link Router Flaws CVE-2023-50224 and CVE-2025-9377 as Actively Exploited The Hacker News
175 Malicious npm Packages with 26,000 Downloads Used in Credential Phishing Campaign 175 Malicious npm Packages with 26,000 Downloads Used in Credential Phishing Campaign The Hacker News
Chinese Hacker Xu Zewei Arrested for Ties to Silk Typhoon Group and U.S. Cyber Attacks Chinese Hacker Xu Zewei Arrested for Ties to Silk Typhoon Group and U.S. Cyber Attacks The Hacker News
WhatsApp Worm, Critical CVEs, Oracle 0-Day, Ransomware Cartel & More WhatsApp Worm, Critical CVEs, Oracle 0-Day, Ransomware Cartel & More The Hacker News
MOVEit Transfer Faces Increased Threats as Scanning Surges and CVE Flaws Are Targeted MOVEit Transfer Faces Increased Threats as Scanning Surges and CVE Flaws Are Targeted The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Cyber Attacks Exploit WinRAR Flaw Against Ukraine
  • Phishing Scams Exploit AI Tool Brands for Credential Theft
  • Shai-Hulud Supply Chain Attacks Target NPM and PyPI Packages
  • Unveiling the Hidden Risks in Network Security Operations
  • Microsoft Defender Enhances RPC Protocol Security

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Cyber Attacks Exploit WinRAR Flaw Against Ukraine
  • Phishing Scams Exploit AI Tool Brands for Credential Theft
  • Shai-Hulud Supply Chain Attacks Target NPM and PyPI Packages
  • Unveiling the Hidden Risks in Network Security Operations
  • Microsoft Defender Enhances RPC Protocol Security

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark