Russian Hackers Exploit WinRAR Zero-Day to Spread RomCom Malware

1 min read
Source: theregister.com
Russian Hackers Exploit WinRAR Zero-Day to Spread RomCom Malware
Photo: theregister.com
TL;DR Summary

Russia-linked attackers exploited a high-severity WinRAR vulnerability (CVE-2025-8088) before it was patched, using targeted spearphishing campaigns against European and Canadian companies. The vulnerability involves a path-traversal flaw that was exploited via malicious archives containing ADSes, leading to malware deployment and backdoors like Mythic, SnipBot, and RustyClaw. Multiple threat groups, including RomCom and Paper Werewolf, have used this zero-day in targeted attacks, highlighting the importance of timely updates and vigilance.

Share this article

Reading Insights

Total Reads

0

Unique Readers

0

Time Saved

4 min

vs 5 min read

Condensed

92%

91669 words

Want the full story? Read the original article

Read on theregister.com