Two groups exploit WinRAR flaws in separate cyber
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-6218 | Directory Traversal RCE in RARLAB WinRAR RARLAB WinRAR contains a directory traversal flaw (CWE-22) in its handling of file paths within archive files, allowing a crafted archive path to traverse to unintended directories during extraction. Exploitation requires user interaction: the target must open a malicious file (e.g., a booby-trapped archive) or visit a malicious page. A successful attacker executes arbitrary code in the context of the current user, yielding full high-impact code execution on the endpoint (CVSS 3.0: 7.8, local attack vector with required user interaction). Any installation running an affected version of RARLAB WinRAR is exposed; the specific affected version range is not stated in the source data, so defenders should confirm against RARLAB's advisory. The flaw is being actively exploited: CISA added it to the Known Exploited Vulnerabilities catalog on 2025-12-09, Google warned of active exploitation, public reporting ties the campaign to APT-C-08 and at least one other actor group, and EPSS stands at 90.5%. Do: Update WinRAR to the latest vendor release that addresses CVE-2025-6218 per RARLAB's advisory (the fixed version number is not provided in the source data), and treat this as urgent given the KEV listing and 90.5% EPSS. Warn users not to open archives from untrusted or unexpected sources, and inspect email-borne .rar/.zip attachments. Hunt for unusual child processes or file writes outside expected directories following archive extraction, and note U.S. federal civilian agencies must apply mitigations under BOD 22-01. | 7.8 | 91% | KEV PoC ×2 |
| masshundreds of millions of users/installations worldwide | |
| CVE-2025-8088 | WinRAR Path Traversal (CVE-2025-8088) Enables Arbitrary Code Execution A path traversal flaw (CWE-35) in the Windows version of WinRAR allows attackers to achieve arbitrary code execution by delivering a specially crafted archive file that writes outside the expected location when it is opened or processed. Because the CVSS 4.0 vector indicates a local attack requiring user interaction, victims are typically infected by extracting or previewing a malicious archive received via phishing, a malicious download, or another delivery channel. A successful attacker gains the privileges of the user running WinRAR, providing an initial foothold that has been used for both espionage and ransomware operations. Anyone running the Windows version of WinRAR — one of the most widely deployed Windows desktop utilities — is affected, and CPE data additionally lists dtSearch as an affected vendor. Exploitation is confirmed in the wild by nation-state actors (e.g., the China-linked Amaranth-Dragon group per related reporting) and criminal actors including ransomware operators; the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-08-12 and carries a near-maximal 94.6% EPSS score. Do: Update WinRAR to the latest patched release from RARLAB on all Windows endpoints, prioritizing remediation per CISA KEV and BOD 22-01 requirements, and verify that dtSearch deployments bundling the affected component are also updated. Because exploitation requires a user to open or extract a crafted archive, warn users to treat unexpected archive files delivered by email or download with suspicion. Given confirmed ransomware use, hunt across user workstations — not just exposed servers — for suspicious archive-based infections and confirm the patched WinRAR version is installed. | 8.4 | 95% | KEV ransomware |
| masshundreds of millions of Windows users/devices (est.; RARLAB has historically claimed user counts in the hundreds of millions) |
Full article604 words · extracted from therecord.media · click to collapse
Two different threat actors, including a Russia-aligned cyber-espionage group, exploited vulnerabilities in the popular WinRAR file-archiving software this summer, researchers have found. Slovak cybersecurity firm ESET said in a report on Monday that Russia-aligned RomCom, also tracked as Storm-0978, was the first to exploit a newly discovered flaw in WinRAR, tracked as CVE-2025-8088. The vulnerability, which allows attackers to execute code on a victim’s system after getting them to open a malicious archive file, was patched on July 24 — just six days after ESET discovered it. RomCom spearphished people at financial, manufacturing, defense and logistics companies in Europe and Canada, the report said. The attackers sent emails containing a malicious résumé file, hoping recipients would open it, but ESET said it could not confirm any successful compromises. According to the company, the targeted industries match the usual focus of Russian-backed espionage groups, indicating a likely geopolitical motive. “This is at least the third time that RomCom has been caught exploiting a significant zero-day vulnerability in the wild,” researchers said. In 2023, the group targeted European defense and government entities using a Microsoft Word flaw, and in 2024, it used a previously unknown Firefox bug to deploy its backdoor malware. In a separate report last week, researchers at Russian cybersecurity firm BI.ZONE said the little-known group Paper Werewolf, also tracked as Goffee, exploited a zero-day flaw along with a known vulnerability in WinRAR in recent attacks on Russian organizations. ESET said on Monday that the zero-day cited in BI.ZONE’s report appears to be the same WinRAR bug uncovered during the RomCom research. “This second threat actor began exploiting CVE-2025-8088 a few days after RomCom started doing so,” ESET said, adding that it was aware the vulnerability has also been exploited by another group and was independently discovered by Russian researchers. BI.ZONE suspects that Paper Werewolf may have acquired a zero-day exploit for WinRAR on a Russian-language darknet forum, where it was reportedly sold for $80,000. The previously known WinRAR bug in the BI.ZONE report, tracked as CVE-2025-6218, was fixed in June. It allows attackers to run arbitrary code with the same privileges as the user if they open a booby-trapped file or visit a compromised website. According to BI.ZONE, Paper Werewolf’s attacks in July and August targeted Russian organizations through phishing emails impersonating employees of the All-Russian Research Institute. The emails carried malicious RAR archives that, once opened, exploited the vulnerabilities to gain access to victims’ systems. BI.ZONE did not disclose details about the targeted organizations or whether the attacks were successful. The Moscow-based company was previously sanctioned by the European Union as part of its strategy to counter Russian hybrid threats. It is not clear if RomCom and Paper Werewolf are connected. Researchers have not responded to a request for comment at the time of publication. Paper Werewolf has not been linked to any known nation-state. The group is known for phishing campaigns against Russian institutions, using malicious attachments disguised as official documents. In April, Kaspersky reported that the group used custom malware, PowerModul, to steal files from flash drives connected to Russian computers. Although espionage is believed to be Paper Werewolf’s main goal, BI.ZONE reported at least one incident in which the group disrupted operations within a compromised network.
No previous article
No new articles
Daryna Antoniuk
is a reporter for Recorded Future News based in Ukraine. She writes about cybersecurity startups, cyberattacks in Eastern Europe and the state of the cyberwar between Ukraine and Russia. She previously was a tech reporter for Forbes Ukraine. Her work has also been published at Sifted, The Kyiv Independent and The Kyiv Post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/winrar-zero-day-exploited-romcom-paper-werewolf-goffee-hackers