Target Industry

Finance, manufacturing, defence and logistics organisations in Europe and Canada; additional activity observed against organisations in Russia. Broader risk to any Windows environment using vulnerable WinRAR/RAR/UnRAR components.

Overview

A path traversal flaw in WinRAR for Windows, tracked as CVE‑2025‑8088 (reported CVSS 8.8), enables arbitrary code execution via specially crafted archives. The issue affects WinRAR, the Windows RAR utilities, UnRAR.dll and the portable UnRAR Windows source. A fix shipped in WinRAR 7.13 on 30th July 2025.

Impact

Exploitation can force files to be written outside the intended extraction directory, including to autorun locations (e.g., the Windows Startup folder), enabling persistence and subsequent code execution at next logon. Campaigns observed by researchers deploy malicious DLLs and LNK files during extraction to achieve execution and persistence.

Affected Products

Windows versions of WinRAR, RAR, UnRAR.dll and the portable UnRAR Windows source up to and including 7.12. Patched in WinRAR 7.13.

Exploitation

  • RomCom (aka Storm‑0978/Void Rabisu/UNC2596) exploited CVE‑2025‑8088 as a zero‑day from 18th to 21st July 2025, delivering SnipBot variants, RustyClaw and a Mythic agent via CV‑themed phishing archives that abuse NTFS alternate data streams (ADS)
  • Paper Werewolf (aka GOFFEE) used phishing archives against Russian organisations in July, leveraging CVE‑2025‑6218 (directory traversal; patched in June) and likely CVE‑2025‑8088 in later waves

Containment, Mitigations & Remediations

  1. Patch immediately to WinRAR 7.13 or later on all Windows systems; WinRAR has no auto‑update, so manual updates are required
  2. Email controls: temporarily quarantine or block inbound RAR archives; apply heightened inspection for ADS‑abusing archives
  3. Threat Hunting: hunt for IOCs, newly created .LNK files under Startup paths and suspicious DLLs in %TEMP% following archive extraction
  4. Hardening: enforce application allow‑listing, restrict write/execute in user profile paths where feasible, and monitor for COM hijacking indicators

Threat Landscape

Multiple Russian‑aligned actors are exploiting WinRAR traversal flaws in close succession (CVE‑2025‑6218 and CVE‑2025‑8088). The presence of a dark‑web listing for a WinRAR zero‑day at $80,000 underscores exploit market demand and the likelihood of further copycat activity.

Further Information

WinRAR bulletin

Intelligence Terminology Yardstick

Further Threat Intelligence from Quorum Cyber

Headquarters

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

FLORIDA, USA Office

501 E Kennedy Blvd.
STE 1400
Tampa FL 33602

Ontario, Canada Office

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

Contact Us
Address

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

501 E Kennedy Blvd
STE 1400
Tampa FL 33602

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

HEADQUARTERS
Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ



FLORIDA, USA OFFICE
501 E Kennedy Blvd.
STE 1400
Tampa FL 33602


ONTARIO, CANADA OFFICE
1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7


Legal

Privacy Preference Center

Skip to content