Nearly a year after patches for the vulnerability were made available, two cyberattack campaigns with ties to Russia have persisted in using a WinRAR security hole to target Ukrainian organizations.
Trend Micro has identified Earth Dahu (also known as Gamaredon) and SHADOW-EARTH-066 (also known as UAC-0226) as the cause of the activity. It involves taking use of CVE-2025-8088, a path traversal vulnerability that enables an attacker to use NTFS Alternate Data Streams (ADS) to write files outside of the extraction directory. In July 2025, WinRAR patched it.
The results demonstrate “how unmanaged software keeps an exploited entry point open long after the fix ships,” according to an investigation released on Monday by Trend Micro researchers Hiroyuki Kakara and Feike Hacquebord.
SHADOW-EARTH-066’s WinRAR exploit chain differs from Excel macro droppers that the threat actor previously used to distribute GIFTEDCROOK read more about WinRAR Flaw Exploited by Russia-Aligned Groups to Deploy Stealers in Ukraine
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
