A Russian threat group has exploited a zero-day vulnerability in WinRAR (CVE-2025-8088) to conduct a cyberespionage campaign targeting European and Canadian organizations. The vulnerability was quickly patched after discovery, with attackers using spearphishing emails to deliver malicious archives. #WinRARZeroDay #RomCom #CyberEspionage #CVE20258088 #EuropeanOrganizations #CanadianOrganizations
Keypoints
- The threat group RomCom exploited a zero-day vulnerability in WinRAR for cyberespionage campaigns.
- The vulnerability, CVE-2025-8088, involves a path traversal flaw using alternate data streams.
- Attackers used spearphishing emails with malicious archives disguised as resumes to target specific individuals.
- The attacks aimed at sectors including finance, defense, manufacturing, and logistics across Europe and Canada.
- The vulnerability was patched with a security update released shortly after detection by ESET.
Read More: https://www.securityweek.com/russian-hackers-exploited-winrar-zero-day-in-attacks-on-europe-canada/