Close Menu
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    • Blogging
    • SEO & Digital Marketing
    • WiFi / Internet & Networking
    • Cybersecurity
    • Tech Tools & Mobile / Apps
    • Privacy & Online Earning
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    Home»Cybersecurity»WinRAR vulnerability still a go-to tool for hackers, Mandiant warns
    Cybersecurity

    WinRAR vulnerability still a go-to tool for hackers, Mandiant warns

    adminBy adminJanuary 28, 2026No Comments2 Mins Read
    Facebook Twitter LinkedIn Telegram Pinterest Tumblr Reddit WhatsApp Email
    WinRAR vulnerability still a go-to tool for hackers, Mandiant warns
    Share
    Facebook Twitter LinkedIn Pinterest Email

    State-sponsored hackers and financially motivated attackers continue leveraging a critical WinRAR vulnerability (CVE-2025-8088) that’s been fixed over half a year ago.

    CVE-2025-8088 is a path traversal vulnerability that can be exploited via maliciously crafted RAR archives.

    “The exploit chain often involves concealing the malicious file within the ADS of a decoy file inside the archive. While the user typically views a decoy document (such as a PDF) within the archive, there are also malicious ADS entries, some containing a hidden payload while others are dummy data,” the Mandiant researchers explained.

    “When the archive is opened, the ADS content (malicious.lnk) is extracted to the destination specified by the traversal path, automatically executing the payload the next time the user logs in.”

    Exploit supplier fuels WinRAR attacks

    In July and August 2025, researchers spotted CVE‑2025‑8088 being leveraged by the RomCom (aka Storm-0978) hackers and the Paper Werewolf (aka Goffee) attack group.

    BI.ZONE researchers posited that both groups got their exploit from the same vendor: “zeroplayer”, an exploit supplier that advertizes on dark web forums.

    CVE-2025-8088 exploited

    WinRAR zero-day exploit for sale (Source: BI.ZONE)

    Since those earliest attacks, other threat actors have been spotted exploiting (or attempting to exploit) CVE-2025-8088:

    • Several Russian-nexus APTs, for cyber espionage purposes against Ukrainian targets: Sandworm (aka APT44), Trula (aka Secret Blizzard), and TEMP.Armageddon (aka CARPATHIAN)
    • An unspecified China-Nexus threat actor to deliver the POISONIVY (aka Darkmoon) remote access trojan
    • Financially motivated groups that targeted entities in Indonesia, organizations in the hospitality and travel sectors in Latin America, and users of banking websites of two Brazilian banks

    The malware delivered via these booby-trapped archive files varies from malicious Chrome extensions to backdoors and commodity RATs and information-stealing malware, but the attacks continue to this day.

    “By providing ready-to-use capabilities, actors such as zeroplayer reduce the technical complexity and resource demands for threat actors, allowing groups with diverse motivations—from ransomware deployment to state-sponsored intelligence gathering—to leverage a diverse set of capabilities,” Mandiant researchers noted.

    Users of the popular archiving utility – and there are several hundred millions of them out there – should download and install WinRAR 7.13, which contains fixes for both CVE‑2025‑8088 and another known exploited flaw (CVE‐2025‐6218).

    (WinRAR doesn’t have an automatic update feature. A new version must be downloaded and installed over the existing installation.)

    Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

    goto hackers Mandiant tool vulnerability warns WinRAR
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email
    Previous ArticleGoogle May Let Sites Opt Out Of AI Search Features
    Next Article Semantic Search Is the Only Search That Matters Now (For SEO and AI Visibility)
    admin
    • Website

    Related Posts

    Google Develops Merkle Tree Certificates to Enable Quantum-Resistant HTTPS in Chrome

    March 3, 2026

    Meta AI in WhatsApp organizes chats and reopens privacy issues

    March 3, 2026

    University of Mississippi Medical Center reopens clinics after ransomware attack

    March 3, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Search Blog
    About
    About

    At WifiPortal.tech, we share simple, easy-to-follow guides on cybersecurity, online privacy, and digital opportunities. Our goal is to help everyday users browse safely, protect personal data, and explore smart ways to earn online. Whether you’re new to the digital world or looking to strengthen your online knowledge, our content is here to keep you informed and secure.

    Trending Blogs

    Google Develops Merkle Tree Certificates to Enable Quantum-Resistant HTTPS in Chrome

    March 3, 2026

    EFF to Court: Don’t Make Embedding Illegal

    March 3, 2026

    Google uses both schema.org markup and og:image meta tag for thumbnails in Google Search and Discover

    March 3, 2026

    5 phones that are better than the Google Pixel 10a

    March 3, 2026
    Categories
    • Blogging (32)
    • Cybersecurity (566)
    • Privacy & Online Earning (78)
    • SEO & Digital Marketing (354)
    • Tech Tools & Mobile / Apps (702)
    • WiFi / Internet & Networking (102)

    Subscribe to Updates

    Stay updated with the latest tips on cybersecurity, online privacy, and digital opportunities straight to your inbox.

    WifiPortal.tech is a blogging platform focused on cybersecurity, online privacy, and digital opportunities. We share easy-to-follow guides, tips, and resources to help you stay safe online and explore new ways of working in the digital world.

    Our Picks

    Google Develops Merkle Tree Certificates to Enable Quantum-Resistant HTTPS in Chrome

    March 3, 2026

    EFF to Court: Don’t Make Embedding Illegal

    March 3, 2026

    Google uses both schema.org markup and og:image meta tag for thumbnails in Google Search and Discover

    March 3, 2026
    Most Popular
    • Google Develops Merkle Tree Certificates to Enable Quantum-Resistant HTTPS in Chrome
    • EFF to Court: Don’t Make Embedding Illegal
    • Google uses both schema.org markup and og:image meta tag for thumbnails in Google Search and Discover
    • 5 phones that are better than the Google Pixel 10a
    • Meta AI in WhatsApp organizes chats and reopens privacy issues
    • 11 Best Small Business Checking Accounts of March 2026
    • Voice Search Ads Are Changing Google’s Search Term Report
    • 7 new horror movies on Netflix, Shudder, HBO Max, and more in March 2026
    © 2026 WifiPortal.tech. Designed by WifiPortal.tech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer

    Type above and press Enter to search. Press Esc to cancel.