WinRAR Flaw Exploited by Russia-Aligned Groups to Deploy Stealers in Ukraine
Russia-aligned groups are still abusing a WinRAR flaw to infect Ukrainian organizations with stealers, even after the patch shipped in July 2025.
Intelligence analysis by GPT-5.4 Mini

Trend Micro says two Russia-aligned campaigns, Earth Dahu and SHADOW-EARTH-066, are exploiting CVE-2025-8088 in WinRAR to drop malware in Ukraine. The attacks use crafted archives, hidden payloads, and loaders that steal browser data and documents before deleting traces.
Hackers found a hole in a zip-file tool and used it like a secret side door. They hid little trap files inside an archive, then stole saved passwords and documents from computers in Ukraine.
Analysis
What happened
Trend Micro says two Russia-aligned threat activity clusters are continuing to exploit CVE-2025-8088, a WinRAR path traversal flaw patched in July 2025. The issue lets an attacker place files outside the normal extraction folder by abusing NTFS Alternate Data Streams.
One campaign, tracked as SHADOW-EARTH-066 and also known as UAC-0226, has moved away from earlier Excel macro droppers. According to the researchers, the group now uses crafted RAR archives that include a decoy PDF plus hidden payloads in ADS. One of those payloads drops a Windows Shortcut into the Startup folder, so it runs whenever the user logs in. That starts a PowerShell loader through cmd.exe, which then uses in-memory DLL loading to launch an updated version of GIFTEDCROOK.
Trend Micro says the malware steals passwords and cookies from Chromium-based browsers such as Chrome, Edge, and Opera, as well as Firefox. It also hunts for documents with certain extensions and sends the data to an external server before deleting malicious files to reduce forensic traces.
A second group, Earth Dahu also known as Gamaredon, has used the same flaw since at least September 2025. Trend Micro says this campaign uses an HTA-to-VBScript chain that delivers espionage modules, and that the activity appears to have continued through at least April 10, 2026. Sekoia separately documented a related chain last week involving GammaPhish, GammaLoad, and GammaSteel.
Why this stands out
The reporting suggests this is not a one-off exploit but an ongoing abuse pattern. It also shows how a single unpatched or unmanaged application can stay attractive long after a fix is available, especially in environments where WinRAR is deeply embedded in daily work.
Key points
- Trend Micro says Earth Dahu and SHADOW-EARTH-066 are both exploiting WinRAR CVE-2025-8088 against Ukrainian targets.
- The flaw was patched in July 2025, but the campaigns were still active months later.
- SHADOW-EARTH-066 uses crafted RAR files with hidden ADS payloads to launch GIFTEDCROOK.
- GIFTEDCROOK steals browser passwords, cookies, and selected documents, then erases traces.
- Earth Dahu has used the same flaw since at least September 2025 and remains active through April 2026, according to Trend Micro.
If organizations fully patch WinRAR and block risky archive handling, this attack path becomes much less useful. The shift away from Telegram also gives defenders more specific server activity to hunt for and disrupt.
If organizations keep running old versions or do not monitor archive-based infection chains, the same flaw can keep working against them. The use of hidden payloads, startup persistence, and file cleanup makes these intrusions harder to spot and investigate.



