CVE-2025-8088: How RomCom exploited a zero-day vulnerability in WinRAR – Details, impact and recommendations
In July–August 2025, ESET researchers discovered a serious zero-day vulnerability in WinRAR, identified as CVE-2025-8088.
1. Introducere
In July-August 2025, researchers from the ESET They discovered a serious zero-day vulnerability. WinRARidentified as CVE-2025-8088.
This was exploited in highly targeted attacks by the group. RomCom and subsequently Paper Werewolfusing spear-phishing campaigns against companies in Europa and Canada.
Although WinRAR is perceived as a simple archiving tool, it runs code on the user’s machine, which means that a vulnerability of this type can be used for Arbitrary execution of code Completion of a system.
Technical details of vulnerability
What is CVE-2025-8088
-
Tip vulnerabilitate: Path Traversal + exploatarea Alternate Data Streams (ADS).
-
Scor CVSS: 8.8 (High).
-
Versiuni afectate: All WinRAR versions up to 7.12 inclusiv.
-
Versiuni sigure: WinRAR 7.13 and subsequent ones.
2.2 How Exploitation Works
-
The attacker creates an archive RAR specially constructed.
-
In the archive is:
-
an apparently legitimate file (e.g. “CV.docx”)
-
files hidden in Alternate Data Streams (ex.: payload.dll:stream)
- When extracting, WinRAR is tricked to place these files in:
-
%TEMP%
-
sau folderul Startup (%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup)
- At the next login, the payload runs automatically, giving the attacker acces persistent.
2.3 The key point of vulnerability
-
WinRAR does not correctly check the file path to extract.
-
ADSs were treated like regular files without cross-path filtration.
3. Cronologia incidentului
Data
Eveniment
The actors involved
4.1 RomCom (Storm-0978 / UNC2596)
-
Grup de APT asociat intereselor pro-ruse.
-
Specialized in attacks on critical infrastructure, logistics and defense.
-
Payload-uri folosite:
-
SnipBot RAT for remote control.
-
RustyClaw – backdoor modular.
-
Mythic agent – framework post-exploitation.
-
4.2 Paper Werewolf (Goffee)
-
Group suspected of buying the exploit (~80,000 USD on the darknet).
-
He used it in attacks on Russian organizations, combined with CVE-2025-6218.
5. Vectorii de atac
The main method: spear-phishing
-
Personalized emails with recruitment topics or partnership offers.
-
RAR attachments masked as CV-uri sau documente comerciale.
5.2 Exploatarea post-intrare
-
The extracted payloads create persistence.
-
C2 connections are established to external servers controlled by attackers.
-
The data is gradually exfiltrated to avoid detection.
6. Indicatori de Compromitere (IoCs)
The Suspicious Files:
-
Unknown in Startup.
-
Unknown DLLs in %TEMP% or %LOCALAPPDATA%.
The Network Activity:
-
New areas with short TTL.
-
Encrypted traffic to IPs outside the target region.
7. Impact
-
Completely compromise the target systems.
-
Possible lateral spread in the internal networks.
-
Access to sensitive data (documents, emails, databases).
Security Recommendations
8.1 Immediate action
-
Update WinRAR version 7.13+ on all systems.
-
Full scan with up-to-date AV/EDR solutions.
-
Blocare executabilelor din foldere temporare.
8.2 Long term prevention
-
Implementarea sandboxing pentru deschiderea arhivelor necunoscute.
-
Restricting macros and auto-run scripts.
-
Campanii regulate de awareness against spear phishing.
9. Concluzie
Incidentul CVE-2025-8088 It demonstrates how a daily utility can become a critical attack vector.
The Rapid Reaction – patch application and staff training – is the only way to prevent compromise in the chain.
ZebraByteeditorial material on digital security, infrastructure, privacy and compliance, kept in the company's technical archive.