INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Everybody is WinRAR Exploitation

| 2026-01-28 18:59 CRITICAL HIGH
Executive Summary AI-generated
The WinRAR vulnerability, CVE-2025-8088, has been exploited by various groups to bring infostealers and Remote Access Trojans (RATs) to targeted sectors. The threat hunters have identified multiple Kremlin-linked crews abusing the flaw in Ukraine, while commercial organizations are also being targeted through phishing emails with hotel booking lures delivering XWorm and AsyncRAT malware. Government-backed actors have adopted the exploit for military, government, and technology targets, including a ransomware and espionage gang targeting Ukrainian entities using geopolitical lures. The vulnerability has been patched by WinRAR in version 7.13 released on July 30, but several groups are still abusing it as of late January.
Technical Mitigations AI-generated
* Use up-to-date and patched versions of WinRAR, such as version 7.13 or later, to ensure that the path traversal flaw is fixed. * Regularly update operating systems and software to ensure that any known vulnerabilities are addressed before they can be exploited by threat actors. * Implement robust security measures, such as secure file paths and access controls, to prevent unauthorized access to sensitive data even if malware is dropped into arbitrary locations on a system. * Use anti-malware software and keep it up-to-date with the latest signatures and definitions to detect and remove threats like Remote Access Trojans (RATs) and infostealers that may be compromised by this vulnerability.
Technical Observables
AI Podcast (EN) detail_available
detail_listen_ai (EN)
Intelligence distributed on:
Incident Link
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
TurlaTurla PoisonIvyPoisonIvyPoison IvyPoison IvyCubaCuba CVE-2025-8088CVE-2025-8088 CVE-2025-6218CVE-2025-6218
Target & Sectors
CU CN RU UA BR ID
governmentgovernment hospitalityhospitality technologytechnology
Incident Timeline
July 18, 2025
Threat actors used a zero-day exploit in Everybody to target General Document Context ESET.
tactic Espionage
organisation ESET
organisation RomCom
organisation CIGAR
organisation SnipBot
organisation NESTPACKER
July 2025
Threat actors exploited the Everybody is WinRAR vulnerability to target various entities across different operations.
source_region Russian Federation
source_region China
industry Government
attribution the Google Threat Intelligence Group
July 30, 2025
Threat actors exploited the CVE-2025-8088 vulnerability in WinRAR to release a rapidly spreading RAT.
vulnerability CVE-2025-8088
infrastructure Winrar
infrastructure 8.8
infrastructure 7.13
general_metric 8.8 score
general_metric 7.13 WinRAR version
November 2025
Threat actors used a zero-day exploit for Windows to remotely execute code on targeted systems, which they also exploited using Privilege Escalation techniques.
infrastructure Windows
tactic Privilege Escalation
organisation Microsoft Office
tactic Remote Code Execution
organisation LPE
financial $100,000 Windows
Jan 28, 2026
Threat actors used Everybody to target General Document Context.
Jan 28
Threat actors exploited a now-patched critical security flaw in RARLAB WinRAR to establish initial access and deploy payloads.
infrastructure Winrar
attribution Vulnerability / Threat Intelligence
attribution RARLAB WinRAR
2026-01-28
Threat actors exploited a path traversal flaw in the Windows version of WinRAR to drop malware, including ransomware and espionage tools.
infrastructure Windows
threat_actor Turla
infrastructure Winrar
organisation Google
organisation BAT
organisation CVE-2025
organisation Kremlin
organisation Summit
organisation LNK
organisation Alternate Data Streams
organisation ADS
organisation ESET
organisation The Register
organisation Industrial Spy
organisation XWorm
organisation WinRAR
organisation CVSS
organisation Gamaredon
organisation RAR
organisation PDF
July 30
WinRAR patched the vulnerability in version 7.13 on July 30, which received an 8.8 CVSS v3.1 score.
infrastructure Winrar
infrastructure 8.8
infrastructure 7.13
general_metric 7.13 WinRAR version
Tactical Metrics
Metrics
infrastructure
​Windows
Affected Product
Metrics
infrastructure
​Winrar
Affected Product
Metrics
infrastructure
​8.8
Software Version
Metrics
infrastructure
​7.13
Software Version
Metrics
infrastructure
​Microsoft Office
Affected Product
Metrics
financial
100,000
Windows
Intelligence Sources
The Register - Cybercrime 2026-01-28