Russian Hackers Exploited WinRAR Zero-Day in Attacks on Europe, Canada

Russian Hackers Exploited WinRAR Zero-Day in Attacks on Europe, Canada

A Russian threat group has exploited a zero-day vulnerability in WinRAR (CVE-2025-8088) to conduct a cyberespionage campaign targeting European and Canadian organizations. The vulnerability was quickly patched after discovery, with attackers using spearphishing emails to deliver malicious archives. #WinRARZeroDay #RomCom #CyberEspionage #CVE20258088 #EuropeanOrganizations #CanadianOrganizations

Keypoints

  • The threat group RomCom exploited a zero-day vulnerability in WinRAR for cyberespionage campaigns.
  • The vulnerability, CVE-2025-8088, involves a path traversal flaw using alternate data streams.
  • Attackers used spearphishing emails with malicious archives disguised as resumes to target specific individuals.
  • The attacks aimed at sectors including finance, defense, manufacturing, and logistics across Europe and Canada.
  • The vulnerability was patched with a security update released shortly after detection by ESET.

Read More: https://www.securityweek.com/russian-hackers-exploited-winrar-zero-day-in-attacks-on-europe-canada/