discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.
Featured

WinRAR Flaw Exploited by Russia-Aligned Groups to Deploy Stealers in Ukraine

Russia-aligned groups are still abusing a WinRAR flaw to infect Ukrainian organizations with stealers, even after the patch shipped in July 2025.

By Ravie Lakshmanan·Jun 9·thehackernews.com·2 min read

Intelligence analysis by GPT-5.4 Mini

WinRAR Flaw Exploited by Russia-Aligned Groups to Deploy Stealers in Ukraine
Image: thehackernews.com

Trend Micro says two Russia-aligned campaigns, Earth Dahu and SHADOW-EARTH-066, are exploiting CVE-2025-8088 in WinRAR to drop malware in Ukraine. The attacks use crafted archives, hidden payloads, and loaders that steal browser data and documents before deleting traces.

Why it matters

This is a live example of how a patched vulnerability can remain dangerous for months when software is not updated everywhere. It also shows multiple state-linked groups converging on the same weakness against targets in Ukraine.

Hackers found a hole in a zip-file tool and used it like a secret side door. They hid little trap files inside an archive, then stole saved passwords and documents from computers in Ukraine.

Analysis

What happened

Trend Micro says two Russia-aligned threat activity clusters are continuing to exploit CVE-2025-8088, a WinRAR path traversal flaw patched in July 2025. The issue lets an attacker place files outside the normal extraction folder by abusing NTFS Alternate Data Streams.

One campaign, tracked as SHADOW-EARTH-066 and also known as UAC-0226, has moved away from earlier Excel macro droppers. According to the researchers, the group now uses crafted RAR archives that include a decoy PDF plus hidden payloads in ADS. One of those payloads drops a Windows Shortcut into the Startup folder, so it runs whenever the user logs in. That starts a PowerShell loader through cmd.exe, which then uses in-memory DLL loading to launch an updated version of GIFTEDCROOK.

Trend Micro says the malware steals passwords and cookies from Chromium-based browsers such as Chrome, Edge, and Opera, as well as Firefox. It also hunts for documents with certain extensions and sends the data to an external server before deleting malicious files to reduce forensic traces.

A second group, Earth Dahu also known as Gamaredon, has used the same flaw since at least September 2025. Trend Micro says this campaign uses an HTA-to-VBScript chain that delivers espionage modules, and that the activity appears to have continued through at least April 10, 2026. Sekoia separately documented a related chain last week involving GammaPhish, GammaLoad, and GammaSteel.

Why this stands out

The reporting suggests this is not a one-off exploit but an ongoing abuse pattern. It also shows how a single unpatched or unmanaged application can stay attractive long after a fix is available, especially in environments where WinRAR is deeply embedded in daily work.

Key points

  • Trend Micro says Earth Dahu and SHADOW-EARTH-066 are both exploiting WinRAR CVE-2025-8088 against Ukrainian targets.
  • The flaw was patched in July 2025, but the campaigns were still active months later.
  • SHADOW-EARTH-066 uses crafted RAR files with hidden ADS payloads to launch GIFTEDCROOK.
  • GIFTEDCROOK steals browser passwords, cookies, and selected documents, then erases traces.
  • Earth Dahu has used the same flaw since at least September 2025 and remains active through April 2026, according to Trend Micro.
The Upside

If organizations fully patch WinRAR and block risky archive handling, this attack path becomes much less useful. The shift away from Telegram also gives defenders more specific server activity to hunt for and disrupt.

The Downside

If organizations keep running old versions or do not monitor archive-based infection chains, the same flaw can keep working against them. The use of hidden payloads, startup persistence, and file cleanup makes these intrusions harder to spot and investigate.

Originally reported at

thehackernews.com

Discernion covers the story. Read the full piece at the source.

Tagssecuritycyber-espionagemalwarevulnerabilityrussiaukraine

Author

Ravie Lakshmanan

Intelligence analysis by

GPT-5.4 Mini

Published

Jun 9, 2026

Source

thehackernews.com

Share

Topics

securitycyber-espionagemalwarevulnerabilityrussiaukraine

Related

More from this desk

Jul 29·thehackernews.com

Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory

A maximum-severity security flaw in Ruflo, an open-source agent meta-harness for Anthropic Claude Code and OpenAI Codex, allows unauthenticated remote code execution. The vulnerability, tracked as CVE-2026-59726, impacts all versions of the project before version 3.16.3.

Jul 29·thehackernews.com

Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape

Broadcom patched three critical VMware vulnerabilities including two CVSS 9.8 flaws in vCenter for auth bypass and arbitrary code execution, plus a VMXNET3 flaw enabling VM escape.

Jul 29·bleepingcomputer.com

Hackers target over 30 Minnesota water utilities in coordinated OT attack

Hackers targeted over 30 Minnesota water utilities in a coordinated cyberattack, disrupting operational technology systems. The Minnesota IT Services agency is working with federal and state partners to investigate and fortify the security of the state's critical infrastr…

Jul 29·bleepingcomputer.com

Your AI Agents Are Guessing at Scale: Permissions Decide the Damage

AI agents are designed to improvise, but this can lead to security risks when paired with broad access. Teams struggle to apply least privilege to agents, and traditional security models break down. Token Security offers a solution to discover and map risky access, and au…