Russia-aligned hackers are still exploiting WinRAR CVE-2025-8088 against Ukrainian organizations nearly a year after patches shipped.

Russia-aligned hackers are still exploiting WinRAR CVE-2025-8088 against Ukrainian organizations nearly a year after patches shipped.

Two separate campaigns target CVE-2025-8088, fixed last July, to conduct data theft and cyberespionage against military and government targets in Ukraine

Gamaredon and SHADOW-EARTH-066 are exploiting CVE-2025-8088 in WinRAR to steal credentials and documents from Ukrainian targets, nearly a year after a patch.