- Joined
- Jan 22, 2026
- Messages
- 101
- Reaction score
- 921
Just one wrong archive can ruin your career and empty your bank account.

The Google Threat Intelligence Group team reported on the large-scale exploitation of the critical vulnerability CVE-2025-8088 in the popular WinRAR archiver. Despite the fact that the problem was fixed in the summer of 2025, hackers continue to actively use it in attacks around the world, using it both in financially motivated campaigns and in operations related to government agencies in different countries.
We are talking about a path-traversal error that allows you to write files to arbitrary Windows directories, including the startup folder, through specially generated RAR archives. To do this, an alternative data flow mechanism is used when a malicious file is disguised inside an innocuous document, such as a PDF. When opening the archive, the hidden object is imperceptibly saved in the system directory, and then automatically launched the next time the user logs in, ensuring that the attack is fixed in the system and further developed.
According to GTIG, the operation of CVE-2025-8088 began on July 18, 2025, and the fix was released by RARLAB on July 30 along with WinRAR version 7.13. However, the low software update rate among users and organizations made this vulnerability a convenient tool for mass attacks.
The attacks use phishing mailings, archives with baits on Ukrainian subjects and malicious shortcuts, scripts and HTA files that download additional components. These operations have documented the use of the NESTPACKER, STOCKSTAY, and other malware families for intelligence and remote management.
The vulnerability is actively exploited by both government and private hacker groups. Attacks have been recorded against organizations in Indonesia, Latin America, and Brazil, where RAT programs, data thieves, backdoors, and even malicious Chrome browser extensions that embed phishing scripts on banking websites are distributed through WinRAR.
The report pays special attention to the underground exploit market. According to GTIG, a significant role in the spread of such tools is played by an actor under the pseudonym zeroplayer, which has been offering various expensive exploits on the black market since 2025, including vulnerabilities in Microsoft Office, Windows, VPN solutions and security systems. This speeds up the launching of attacks on the stream, lowering the entry threshold for a wide variety of groups.
Google emphasizes that the situation around CVE-2025-8088 clearly shows how dangerous already closed vulnerabilities remain if they quickly enter the criminal ecosystem. Even after the release of updates, such gaps have been used for years in real attacks, becoming a universal vector of initial penetration into systems.

The Google Threat Intelligence Group team reported on the large-scale exploitation of the critical vulnerability CVE-2025-8088 in the popular WinRAR archiver. Despite the fact that the problem was fixed in the summer of 2025, hackers continue to actively use it in attacks around the world, using it both in financially motivated campaigns and in operations related to government agencies in different countries.
We are talking about a path-traversal error that allows you to write files to arbitrary Windows directories, including the startup folder, through specially generated RAR archives. To do this, an alternative data flow mechanism is used when a malicious file is disguised inside an innocuous document, such as a PDF. When opening the archive, the hidden object is imperceptibly saved in the system directory, and then automatically launched the next time the user logs in, ensuring that the attack is fixed in the system and further developed.
According to GTIG, the operation of CVE-2025-8088 began on July 18, 2025, and the fix was released by RARLAB on July 30 along with WinRAR version 7.13. However, the low software update rate among users and organizations made this vulnerability a convenient tool for mass attacks.
The attacks use phishing mailings, archives with baits on Ukrainian subjects and malicious shortcuts, scripts and HTA files that download additional components. These operations have documented the use of the NESTPACKER, STOCKSTAY, and other malware families for intelligence and remote management.
The vulnerability is actively exploited by both government and private hacker groups. Attacks have been recorded against organizations in Indonesia, Latin America, and Brazil, where RAT programs, data thieves, backdoors, and even malicious Chrome browser extensions that embed phishing scripts on banking websites are distributed through WinRAR.
The report pays special attention to the underground exploit market. According to GTIG, a significant role in the spread of such tools is played by an actor under the pseudonym zeroplayer, which has been offering various expensive exploits on the black market since 2025, including vulnerabilities in Microsoft Office, Windows, VPN solutions and security systems. This speeds up the launching of attacks on the stream, lowering the entry threshold for a wide variety of groups.
Google emphasizes that the situation around CVE-2025-8088 clearly shows how dangerous already closed vulnerabilities remain if they quickly enter the criminal ecosystem. Even after the release of updates, such gaps have been used for years in real attacks, becoming a universal vector of initial penetration into systems.