The recent discovery of a security flaw in WinRAR, exploited by two Russia-aligned cyber attack campaigns, highlights the ongoing cyber threats faced by Ukraine. This vulnerability, CVE-2025-8088, allows attackers to write files outside the extraction directory via NTFS Alternate Data Streams (ADS), a path traversal flaw patched by WinRAR in July 2025. The exploit chain used by SHADOW-EARTH-066 and Earth Dahu involves crafted RAR archives with hidden payloads, including a Windows Shortcut (LNK) file placed in the Startup folder to automatically execute a PowerShell loader. This loader then launches an updated version of the GIFTEDCROOK information stealer, targeting passwords, cookies, and documents from Chromium-based browsers and Mozilla Firefox. The malware exfiltrates data to external servers and deletes malicious artifacts to cover up the forensic trail.
What makes this particularly fascinating is the shift from Telegram as an exfiltration channel to dedicated command-and-control (C2) servers, a move likely aligned with Russia's blocking of the messaging platform in February. Earth Dahu, known for its industrial-scale efforts to maintain long-term access to compromised organizations, has been using this vulnerability since at least September 2025. The group's use of an HTA-to-VBScript infection chain delivered espionage modules, as noted by Trend Micro, further emphasizes the scale and sophistication of these cyber threats.
The convergence of both established state-backed groups and independently tracked clusters on a single vulnerability reflects the scale of the cyber threats that Ukraine faces. WinRAR's deep integration into daily operations across Ukrainian organizations makes it an attractive target for exploitation. This incident underscores the ongoing challenges and risks faced by Ukraine in the digital domain, requiring constant vigilance and adaptive security measures to mitigate these threats.