Affected Systems
WinRAR versions prior to patched release (approximately one year old). Primary targets: Ukrainian organizations. Threat actors: Earth Dahu (Gamaredon) and SHADOW-EARTH-066 (UAC-0226), Russia-aligned APT groups.
Exploitation Status
Active exploitation confirmed. Russia-aligned APT groups Earth Dahu (Gamaredon) and SHADOW-EARTH-066 (UAC-0226) are weaponizing CVE-2025-8088 in targeted campaigns against Ukrainian entities. Patch available for nearly one year; exploitation indicates unpatched systems remain widespread.
Business Impact
Organizations running outdated WinRAR versions face immediate risk of stealer malware deployment via malicious archives. Path traversal allows attackers to write files outside intended extraction directories, enabling arbitrary code execution. Ukrainian organizations are primary targets, but technique is portable to other regions. Unpatched WinRAR installations represent a persistent attack vector for initial access and payload delivery.
Urgency
🔴 Immediate
Recommended Actions
- Update WinRAR to the latest version immediately on all endpoints; verify patch status via software inventory tools
- Audit all systems for WinRAR installations and enforce centralized patch management for third-party compression utilities
- Block or quarantine unsolicited RAR archives at email gateways; implement user awareness training on risks of opening archives from untrusted sources
- Monitor for suspicious WinRAR process behavior: file writes to startup folders, registry run keys, or system directories outside user-controlled paths
- Hunt for indicators of compromise associated with Earth Dahu and SHADOW-EARTH-066 campaigns, including known stealer families and C2 infrastructure
---
# Threat Actor Context
Actor Profile
Earth Dahu (also tracked as Gamaredon) and SHADOW-EARTH-066 (also tracked as UAC-0226) are Russia-aligned threat actors conducting sustained cyber operations against Ukrainian targets. Both groups are motivated by intelligence collection and espionage objectives aligned with Russian state interests. Earth Dahu/Gamaredon is a well-established APT group with a long operational history targeting Ukraine, while SHADOW-EARTH-066/UAC-0226 represents another Russia-nexus entity focused on Ukrainian government and organizational networks. Both actors demonstrate persistence in exploiting known vulnerabilities even after patches are publicly available, indicating a focus on targets with delayed patch cycles.
TTPs (Tactics, Techniques, Procedures)
The actors exploit CVE-2025-8088, a path traversal vulnerability in WinRAR, to achieve initial access and code execution. This represents exploitation of a public-facing application vulnerability (T1190 - Exploit Public-Facing Application). Following successful exploitation, the actors deploy stealer malware to harvest credentials and sensitive data (T1555 - Credentials from Password Stores, T1005 - Data from Local System). The continued exploitation of a vulnerability nearly a year post-patch suggests targeting of organizations with weak patch management practices and indicates the actors prioritize operational persistence over OPSEC concerns regarding detection through known CVE exploitation.
Targets & Patterns
Both threat actors target Ukrainian government entities and organizations, consistent with Russia-aligned espionage and intelligence collection objectives amid ongoing geopolitical conflict. The focus on Ukraine reflects strategic intelligence requirements related to the Russia-Ukraine conflict. The deployment of stealer malware indicates objectives centered on credential harvesting, document exfiltration, and establishing persistent access to victim networks. The targeting pattern suggests both tactical intelligence collection (operational military/government information) and strategic intelligence gathering (policy documents, communications, organizational structures). The exploitation of a patched vulnerability nearly a year after public disclosure suggests the actors are specifically targeting organizations with limited cybersecurity maturity and delayed patch deployment cycles.
Historical Context
Earth Dahu/Gamaredon has been actively targeting Ukraine since at least 2013-2014, representing one of the most persistent Russia-aligned threat actors focused on Ukrainian entities. The group is known for high-volume, relatively unsophisticated campaigns prioritizing access over stealth. SHADOW-EARTH-066/UAC-0226 represents a more recently tracked Russia-nexus actor also focused on Ukrainian targets. Both actors' continued operations against Ukraine align with the sustained cyber campaign accompanying the Russia-Ukraine conflict that intensified in 2022. The exploitation of CVE-2025-8088 nearly a year post-patch is consistent with both actors' historical patterns of leveraging known vulnerabilities and publicly available exploits rather than investing in zero-day capabilities, reflecting a volume-over-sophistication operational model.
Defensive Recommendations
- Immediately patch WinRAR to the latest version addressing CVE-2025-8088; prioritize patching on systems handling external file archives
- Implement application allowlisting to prevent unauthorized executables delivered via archive exploitation from executing (mitigates T1204.002)
- Deploy endpoint detection rules monitoring for WinRAR process spawning suspicious child processes (cmd.exe, powershell.exe, wscript.exe) indicative of exploitation
- Monitor for stealer malware indicators including access to credential stores, browser data directories, and unusual file staging/compression activity (detects T1555, T1005, T1560)
- Restrict WinRAR usage via Group Policy where possible; consider alternative archive handlers with stronger security postures for high-risk user populations
---
# Geopolitical Context
Geopolitical Context
The exploitation of CVE-2025-8088 by Russia-aligned threat actors Earth Dahu (Gamaredon) and SHADOW-EARTH-066 (UAC-0226) against Ukrainian government and organizational targets is consistent with sustained cyber operations accompanying the ongoing Russo-Ukrainian conflict. These groups' continued activity reflects Moscow's strategic use of cyber capabilities to maintain intelligence collection and disruptive pressure on Ukrainian state and civil society infrastructure. The exploitation of a patched vulnerability nearly a year after remediation became available underscores persistent challenges in cybersecurity hygiene within resource-constrained environments and the adversary's focus on opportunistic targeting of unpatched systems rather than zero-day development.
State Actor Alignment
Earth Dahu (also tracked as Gamaredon, Armageddon, or Shuckworm) has been publicly attributed by Ukrainian authorities and Western intelligence agencies to Russia's Federal Security Service (FSB). SHADOW-EARTH-066 (UAC-0226) is assessed to be aligned with Russian strategic interests based on targeting patterns and operational tempo against Ukrainian entities. Both groups operate within the broader ecosystem of state-sponsored and state-aligned cyber actors supporting Russian strategic objectives in Ukraine. While not subject to the same level of formal sanctions as military intelligence units, their activities fall within the scope of broader Western sanctions regimes targeting Russian cyber operations and intelligence services.
Business Impacty pro region
For Europe, this activity reinforces the persistent cyber threat environment facing Ukraine and neighboring states, with potential spillover risks to allied networks through supply chain connections or targeting of diaspora communities. The exploitation campaign may prompt renewed emphasis on patch management and endpoint security within EU member states providing material and intelligence support to Ukraine. NATO allies are likely to view this as further evidence of Russia's willingness to sustain multi-domain pressure on Ukraine, informing defensive cyber assistance programs and information sharing arrangements. Globally, the incident illustrates how prolonged conflicts create permissive environments for sustained exploitation of known vulnerabilities, with implications for other contested regions where state-aligned actors operate with relative impunity.
Forecast
If Ukrainian organizations continue to face resource constraints limiting timely patching, Russia-aligned actors are likely to maintain focus on exploiting known vulnerabilities in widely deployed software such as WinRAR. Should Western cyber assistance programs expand endpoint detection and patch management support, the operational window for such exploitation may narrow, potentially driving adversaries toward more sophisticated techniques or alternative initial access vectors. If the conflict remains protracted, Gamaredon and similar groups are expected to sustain intelligence collection operations targeting Ukrainian government and civil society, with periodic shifts in tooling and delivery mechanisms to evade evolving defenses.
