WinRAR Vulnerability CVE-2025-8088 Continues to Be Exploited by Hackers
- Securityish
- Threats & Incidents
Quick Summary
The Securityish Brief
The ongoing exploitation of the WinRAR vulnerability CVE-2025-8088 highlights significant cybersecurity risks for users of this popular archiving utility. Despite a patch being released over six months ago, state-sponsored hackers and financially motivated attackers continue to leverage this path traversal vulnerability. The exploit often involves hiding malicious files within alternate data streams (ADS) of decoy files, such as PDFs, within RAR archives.
In July and August 2025, researchers identified the RomCom (Storm-0978) and Paper Werewolf (Goffee) attack groups utilizing CVE-2025-8088. These groups reportedly obtained their exploit from an exploit supplier known as ‘zeroplayer,’ which operates on dark web forums. This indicates a troubling trend where even less technically skilled threat actors can access sophisticated exploits.
Additionally, various Russian-nexus advanced persistent threats (APTs) have been observed using this vulnerability for cyber espionage against Ukrainian targets, including Sandworm (APT44), Trula (Secret Blizzard), and TEMP.Armageddon (CARPATHIAN). An unspecified China-nexus threat actor has also been linked to delivering the POISONIVY (Darkmoon) remote access trojan through this exploit.
The malware delivered via these compromised archives varies widely, including malicious Chrome extensions, backdoors, and information-stealing malware. This ongoing threat underscores the importance of vigilance among users, especially those in sensitive sectors like finance and hospitality.
With hundreds of millions of WinRAR users globally, the implications of this vulnerability are significant. Users are strongly advised to ensure they are using the latest version, WinRAR 7.13, which addresses both CVE-2025-8088 and another flaw, CVE-2025-6218. Notably, WinRAR does not have an automatic update feature, requiring users to manually download and install updates.
Understanding the Risks
The continued exploitation of CVE-2025-8088 reveals a broader issue of unpatched vulnerabilities being targeted by various threat actors. Organizations and individuals must be aware of the potential risks associated with outdated software and the ease with which attackers can exploit known vulnerabilities.
As threat actors increasingly utilize ready-to-use exploits, the technical barrier for entry into cybercrime diminishes. This trend allows a wider range of actors, from ransomware groups to state-sponsored entities, to leverage sophisticated capabilities without extensive technical knowledge.
Key Takeaways
- Update to WinRAR 7.13 immediately to patch CVE-2025-8088 and CVE-2025-6218.
- Regularly check for software updates, as WinRAR does not automatically update.
- Be cautious when opening RAR files from unknown sources, especially those containing decoy files.
- Monitor for unusual activity on banking and financial accounts, particularly if using WinRAR.
- Educate your team about the risks associated with unpatched software vulnerabilities.
Key Terms & Concepts
- CVE-2025-8088: In this article, CVE-2025-8088 refers to a critical path traversal vulnerability in WinRAR that allows attackers to exploit RAR archives.
- Alternate Data Streams (ADS): In this article, ADS refers to a feature in file systems that allows files to contain multiple streams of data, which can be used to hide malicious content.
- RomCom: In this article, RomCom is an alias for the Storm-0978 hacking group known for exploiting vulnerabilities for malicious purposes.
- Paper Werewolf: In this article, Paper Werewolf is an alias for the Goffee hacking group that has been observed using the WinRAR vulnerability.
- POISONIVY: In this article, POISONIVY refers to a remote access trojan that has been delivered using the WinRAR vulnerability by a China-nexus threat actor.
Your 5-Minute Securityish Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.
Securityish
Securityish explains cybersecurity, scams, data breaches, and privacy risks in simple language so you know what’s happening and how to protect yourself.
Navigation
Your 5-Minute Cybersecurity Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.