Close Menu
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    • Blogging
    • SEO & Digital Marketing
    • WiFi / Internet & Networking
    • Cybersecurity
    • Tech Tools & Mobile / Apps
    • Privacy & Online Earning
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    Home»Cybersecurity»WinRAR vulnerability still a go-to tool for hackers, Mandiant warns
    Cybersecurity

    WinRAR vulnerability still a go-to tool for hackers, Mandiant warns

    adminBy adminJanuary 28, 2026No Comments2 Mins Read
    Facebook Twitter LinkedIn Telegram Pinterest Tumblr Reddit WhatsApp Email
    WinRAR vulnerability still a go-to tool for hackers, Mandiant warns
    Share
    Facebook Twitter LinkedIn Pinterest Email

    State-sponsored hackers and financially motivated attackers continue leveraging a critical WinRAR vulnerability (CVE-2025-8088) that’s been fixed over half a year ago.

    CVE-2025-8088 is a path traversal vulnerability that can be exploited via maliciously crafted RAR archives.

    “The exploit chain often involves concealing the malicious file within the ADS of a decoy file inside the archive. While the user typically views a decoy document (such as a PDF) within the archive, there are also malicious ADS entries, some containing a hidden payload while others are dummy data,” the Mandiant researchers explained.

    “When the archive is opened, the ADS content (malicious.lnk) is extracted to the destination specified by the traversal path, automatically executing the payload the next time the user logs in.”

    Exploit supplier fuels WinRAR attacks

    In July and August 2025, researchers spotted CVE‑2025‑8088 being leveraged by the RomCom (aka Storm-0978) hackers and the Paper Werewolf (aka Goffee) attack group.

    BI.ZONE researchers posited that both groups got their exploit from the same vendor: “zeroplayer”, an exploit supplier that advertizes on dark web forums.

    CVE-2025-8088 exploited

    WinRAR zero-day exploit for sale (Source: BI.ZONE)

    Since those earliest attacks, other threat actors have been spotted exploiting (or attempting to exploit) CVE-2025-8088:

    • Several Russian-nexus APTs, for cyber espionage purposes against Ukrainian targets: Sandworm (aka APT44), Trula (aka Secret Blizzard), and TEMP.Armageddon (aka CARPATHIAN)
    • An unspecified China-Nexus threat actor to deliver the POISONIVY (aka Darkmoon) remote access trojan
    • Financially motivated groups that targeted entities in Indonesia, organizations in the hospitality and travel sectors in Latin America, and users of banking websites of two Brazilian banks

    The malware delivered via these booby-trapped archive files varies from malicious Chrome extensions to backdoors and commodity RATs and information-stealing malware, but the attacks continue to this day.

    “By providing ready-to-use capabilities, actors such as zeroplayer reduce the technical complexity and resource demands for threat actors, allowing groups with diverse motivations—from ransomware deployment to state-sponsored intelligence gathering—to leverage a diverse set of capabilities,” Mandiant researchers noted.

    Users of the popular archiving utility – and there are several hundred millions of them out there – should download and install WinRAR 7.13, which contains fixes for both CVE‑2025‑8088 and another known exploited flaw (CVE‐2025‐6218).

    (WinRAR doesn’t have an automatic update feature. A new version must be downloaded and installed over the existing installation.)

    Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

    goto hackers Mandiant tool vulnerability warns WinRAR
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email
    Previous ArticleGoogle May Let Sites Opt Out Of AI Search Features
    Next Article Semantic Search Is the Only Search That Matters Now (For SEO and AI Visibility)
    admin
    • Website

    Related Posts

    SD-WAN 0-Day, Critical CVEs, Telegram Probe, Smart TV Proxy SDK and More

    March 3, 2026

    AI went from assistant to autonomous actor and security never caught up

    March 3, 2026

    How Microsoft, partners are tackling ‘huge, huge task’ of making security software safer

    March 3, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Search Blog
    About
    About

    At WifiPortal.tech, we share simple, easy-to-follow guides on cybersecurity, online privacy, and digital opportunities. Our goal is to help everyday users browse safely, protect personal data, and explore smart ways to earn online. Whether you’re new to the digital world or looking to strengthen your online knowledge, our content is here to keep you informed and secure.

    Trending Blogs

    Best High-Yield Checking Accounts for March 2026

    March 3, 2026

    This amazing ESP32 projector integrates with Home Assistant and displays whatever you want

    March 3, 2026

    SD-WAN 0-Day, Critical CVEs, Telegram Probe, Smart TV Proxy SDK and More

    March 3, 2026

    Google Clarifies How It Picks Thumbnails For Search, Discover

    March 3, 2026
    Categories
    • Blogging (32)
    • Cybersecurity (572)
    • Privacy & Online Earning (80)
    • SEO & Digital Marketing (357)
    • Tech Tools & Mobile / Apps (709)
    • WiFi / Internet & Networking (103)

    Subscribe to Updates

    Stay updated with the latest tips on cybersecurity, online privacy, and digital opportunities straight to your inbox.

    WifiPortal.tech is a blogging platform focused on cybersecurity, online privacy, and digital opportunities. We share easy-to-follow guides, tips, and resources to help you stay safe online and explore new ways of working in the digital world.

    Our Picks

    Best High-Yield Checking Accounts for March 2026

    March 3, 2026

    This amazing ESP32 projector integrates with Home Assistant and displays whatever you want

    March 3, 2026

    SD-WAN 0-Day, Critical CVEs, Telegram Probe, Smart TV Proxy SDK and More

    March 3, 2026
    Most Popular
    • Best High-Yield Checking Accounts for March 2026
    • This amazing ESP32 projector integrates with Home Assistant and displays whatever you want
    • SD-WAN 0-Day, Critical CVEs, Telegram Probe, Smart TV Proxy SDK and More
    • Google Clarifies How It Picks Thumbnails For Search, Discover
    • These budget-friendly wireless earbuds deliver a pleasant experience while still being easy on the wallet
    • AI went from assistant to autonomous actor and security never caught up
    • Segway Cube 1000 Portable Power Station hits lowest price ever!
    • How Microsoft, partners are tackling ‘huge, huge task’ of making security software safer
    © 2026 WifiPortal.tech. Designed by WifiPortal.tech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer

    Type above and press Enter to search. Press Esc to cancel.