Skip to main content
Back to Blog
August 11, 2025, de Zebrabyte Breaches and incidents

CVE-2025-8088: How RomCom exploited a zero-day vulnerability in WinRAR – Details, impact and recommendations

CVE-2025-8088: How RomCom exploited a zero-day vulnerability in WinRAR – Details, impact and recommendations

In July–August 2025, ESET researchers discovered a serious zero-day vulnerability in WinRAR, identified as CVE-2025-8088.

1. Introducere

In July-August 2025, researchers from the ESET They discovered a serious zero-day vulnerability. WinRARidentified as CVE-2025-8088.

This was exploited in highly targeted attacks by the group. RomCom and subsequently Paper Werewolfusing spear-phishing campaigns against companies in Europa and Canada.

Although WinRAR is perceived as a simple archiving tool, it runs code on the user’s machine, which means that a vulnerability of this type can be used for Arbitrary execution of code Completion of a system.

Technical details of vulnerability

What is CVE-2025-8088

  • Tip vulnerabilitate: Path Traversal + exploatarea Alternate Data Streams (ADS).

  • Scor CVSS: 8.8 (High).

  • Versiuni afectate: All WinRAR versions up to 7.12 inclusiv.

  • Versiuni sigure: WinRAR 7.13 and subsequent ones.

2.2 How Exploitation Works

  1. The attacker creates an archive RAR specially constructed.

  2. In the archive is:

  • an apparently legitimate file (e.g. “CV.docx”)

  • files hidden in Alternate Data Streams (ex.: payload.dll:stream)

  1. When extracting, WinRAR is tricked to place these files in:
  • %TEMP%

  • sau folderul Startup (%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup)

  1. At the next login, the payload runs automatically, giving the attacker acces persistent.

2.3 The key point of vulnerability

  • WinRAR does not correctly check the file path to extract.

  • ADSs were treated like regular files without cross-path filtration.

3. Cronologia incidentului

Data

Eveniment

The actors involved

4.1 RomCom (Storm-0978 / UNC2596)
  • Grup de APT asociat intereselor pro-ruse.

  • Specialized in attacks on critical infrastructure, logistics and defense.

  • Payload-uri folosite:

    • SnipBot RAT for remote control.

    • RustyClaw – backdoor modular.

    • Mythic agent – framework post-exploitation.

4.2 Paper Werewolf (Goffee)

  • Group suspected of buying the exploit (~80,000 USD on the darknet).

  • He used it in attacks on Russian organizations, combined with CVE-2025-6218.

5. Vectorii de atac

The main method: spear-phishing

  • Personalized emails with recruitment topics or partnership offers.

  • RAR attachments masked as CV-uri sau documente comerciale.

5.2 Exploatarea post-intrare

  • The extracted payloads create persistence.

  • C2 connections are established to external servers controlled by attackers.

  • The data is gradually exfiltrated to avoid detection.

6. Indicatori de Compromitere (IoCs)

The Suspicious Files:

  • Unknown in Startup.

  • Unknown DLLs in %TEMP% or %LOCALAPPDATA%.

The Network Activity:

  • New areas with short TTL.

  • Encrypted traffic to IPs outside the target region.

7. Impact

  • Completely compromise the target systems.

  • Possible lateral spread in the internal networks.

  • Access to sensitive data (documents, emails, databases).

Security Recommendations

8.1 Immediate action

  1. Update WinRAR version 7.13+ on all systems.

  2. Full scan with up-to-date AV/EDR solutions.

  3. Blocare executabilelor din foldere temporare.

8.2 Long term prevention

  • Implementarea sandboxing pentru deschiderea arhivelor necunoscute.

  • Restricting macros and auto-run scripts.

  • Campanii regulate de awareness against spear phishing.

9. Concluzie

Incidentul CVE-2025-8088 It demonstrates how a daily utility can become a critical attack vector.

The Rapid Reaction – patch application and staff training – is the only way to prevent compromise in the chain.


Scris de Zebrabyte

ZebraByteeditorial material on digital security, infrastructure, privacy and compliance, kept in the company's technical archive.

ReceiveZebraByteanalytics and guidelines on cyber security, privacy and compliance.
ZebraByte

Framework-uri gestionate Managed frameworks

Can’t find the framework you are looking for?
Talk to us — we may be able to include it in the program.
Don’t see the framework you are looking for?
Reach out – it may already be supported in the program.

SOC 2 Type 1
ISO 27001
ISO 42001
CCPA
GDPR
ISO 27701
HIPAA
FERPA
CASA
SOC 2
Talk to an expert Talk to an expert