URGENT: WinRAR Hack EXPOSED! Russia-Aligned Groups Target Ukraine with Stealer Malware (2026)

The recent discovery of a security flaw in WinRAR, exploited by two Russia-aligned cyber attack campaigns, highlights the ongoing cyber threats faced by Ukraine. This vulnerability, CVE-2025-8088, allows attackers to write files outside the extraction directory via NTFS Alternate Data Streams (ADS), a path traversal flaw patched by WinRAR in July 2025. The exploit chain used by SHADOW-EARTH-066 and Earth Dahu involves crafted RAR archives with hidden payloads, including a Windows Shortcut (LNK) file placed in the Startup folder to automatically execute a PowerShell loader. This loader then launches an updated version of the GIFTEDCROOK information stealer, targeting passwords, cookies, and documents from Chromium-based browsers and Mozilla Firefox. The malware exfiltrates data to external servers and deletes malicious artifacts to cover up the forensic trail.

What makes this particularly fascinating is the shift from Telegram as an exfiltration channel to dedicated command-and-control (C2) servers, a move likely aligned with Russia's blocking of the messaging platform in February. Earth Dahu, known for its industrial-scale efforts to maintain long-term access to compromised organizations, has been using this vulnerability since at least September 2025. The group's use of an HTA-to-VBScript infection chain delivered espionage modules, as noted by Trend Micro, further emphasizes the scale and sophistication of these cyber threats.

The convergence of both established state-backed groups and independently tracked clusters on a single vulnerability reflects the scale of the cyber threats that Ukraine faces. WinRAR's deep integration into daily operations across Ukrainian organizations makes it an attractive target for exploitation. This incident underscores the ongoing challenges and risks faced by Ukraine in the digital domain, requiring constant vigilance and adaptive security measures to mitigate these threats.

URGENT: WinRAR Hack EXPOSED! Russia-Aligned Groups Target Ukraine with Stealer Malware (2026)

References

Top Articles
Latest Posts
Recommended Articles
Article information

Author: Jonah Leffler

Last Updated:

Views: 6118

Rating: 4.4 / 5 (65 voted)

Reviews: 80% of readers found this page helpful

Author information

Name: Jonah Leffler

Birthday: 1997-10-27

Address: 8987 Kieth Ports, Luettgenland, CT 54657-9808

Phone: +2611128251586

Job: Mining Supervisor

Hobby: Worldbuilding, Electronics, Amateur radio, Skiing, Cycling, Jogging, Taxidermy

Introduction: My name is Jonah Leffler, I am a determined, faithful, outstanding, inexpensive, cheerful, determined, smiling person who loves writing and wants to share my knowledge and understanding with you.