High-severity WinRAR 0-day exploited for weeks by 2 groups

High-severity WinRAR 0-day exploited for weeks by 2 groups

A severe zero-day vulnerability in the popular WinRAR file compression software has been actively exploited for several weeks by two distinct cybercrime groups operating out of Russia. These attacks involve backdooring systems that open malicious archives sent via phishing emails, some of which are tailored to individual users. Security firm ESET reported that it first discovered the exploitation on July 18, when unusual telemetry data revealed a file in an atypical directory path. By July 24, ESET confirmed that this behavior was associated with an unknown vulnerability in WinRAR, which boasts an extensive user base of approximately 500 million installations. ESET alerted the developers of WinRAR the same day, resulting in a fix being issued just six days later. The vulnerability exploited by the attackers leveraged alternate data streams, a feature in Windows that allows multiple representations of the same file path. This exploit triggered a previously unidentified path traversal flaw, enabling WinRAR to install malicious executables in locations such as %TEMP% and %LOCALAPPDATA%—directories that Windows typically restricts due to their execution capabilities. ESET identified the attacking group as RomCom, a financially motivated cybercrime organization known for its sophisticated tactics and resourcefulness. This group has a history of leveraging zero-day vulnerabilities and is now linked to the zero-day being tracked as CVE-2025-8088. According to ESET’s experts, this marks at least the third occasion RomCom has deployed a zero-day exploit, indicating their commitment to acquiring and utilizing such vulnerabilities for targeted attacks. Interestingly, RomCom is not alone in exploiting CVE-2025-8088. The Russian security firm Bi.ZONE reported that another group, referred to as Paper Werewolf or GOFFEE, is also taking advantage of this vulnerability. In addition to CVE-2025-8088, this group has been exploiting CVE-2025-6218, another serious WinRAR vulnerability that had been patched five weeks prior to the fix for the latest zero-day issue.

Sources : Ars Technica

Published On : Aug 12, 2025, 06:07

AI
Xi Jinping Advocates for Open-Source AI Collaboration at Global Conference

At the World Artificial Intelligence Conference held in Shanghai, Chinese President Xi Jinping emphasized the necessity ...

Business Insider | Jul 17, 2026, 17:10
Xi Jinping Advocates for Open-Source AI Collaboration at Global Conference
Startups
Market Turmoil: Tech Stocks Plunge, Netflix's Earnings Disappoint, and Economic Sentiment Dips

In a turbulent start to the trading day, stock futures are showing signs of decline after a downward trend yesterday. Th...

CNBC | Jul 17, 2026, 12:45
Market Turmoil: Tech Stocks Plunge, Netflix's Earnings Disappoint, and Economic Sentiment Dips
Computing
Amazon Addresses AWS Billing Glitch Affecting Customers

On Friday, numerous users of Amazon's cloud services were taken aback by unexpected billing estimates indicating they ow...

TechCrunch | Jul 17, 2026, 15:50
Amazon Addresses AWS Billing Glitch Affecting Customers
AI
Kimi K3: China's New AI Challenger Shakes Up Silicon Valley

The launch of Kimi K3, an innovative artificial intelligence model from the Chinese startup Moonshot AI, is creating a s...

Business Insider | Jul 17, 2026, 13:05
Kimi K3: China's New AI Challenger Shakes Up Silicon Valley
AI
AI Startup Secures $400 Million Loan to Pioneer Inference Chip Market

General Compute, an innovative startup specializing in AI inference, has successfully secured a substantial loan of $400...

TechCrunch | Jul 17, 2026, 12:15
AI Startup Secures $400 Million Loan to Pioneer Inference Chip Market
View All News