Skip to content

Mon - Fri: 10.00 - 5.00

[email protected]

Delana Technologies

Delana Technologies

Delana Technologies delivers expert cybersecurity, cloud, and AI-driven IT strategy solutions. Transform your enterprise securely and intelligently.

  • Home
  • Contact Us
  • About Us
  • Case Studies
  • Workflow Automation & Systems Integration
  • AI Consulting & Agentic AI Solutions
  • Home
  • Contact Us
  • About Us
  • Case Studies
  • Workflow Automation & Systems Integration
  • AI Consulting & Agentic AI Solutions

Mon - Fri: 10.00 - 5.00

[email protected]

WinRAR Zero-Day Actively Exploited — CVE-2025-8088

  1. Home   »  
  2. WinRAR Zero-Day Actively Exploited — CVE-2025-8088

WinRAR Zero-Day Actively Exploited — CVE-2025-8088

September 19, 2025September 22, 2026 admincybersecurity

CVE-2025-8088 is a path traversal vulnerability in WinRAR for Windows that lets a malicious archive plant files wherever the attacker chooses, including the Windows Startup folder, so their code runs the next time the user logs in. It was exploited as a zero-day in July 2025 before a fix existed, and it is fixed in WinRAR 7.13. If any machine in your organization runs an older version, it is exposed.

The larger lesson is about the software nobody thinks of as business-critical. WinRAR is a small utility installed on millions of Windows machines, often by users themselves, and it does not update itself. That combination makes it a reliable way into organizations that patch their operating systems and browsers diligently but never look at the rest of the software inventory.

How the vulnerability works

Researchers at ESET discovered the flaw on July 18, 2025, while investigating archives that did not behave the way they looked. The attackers abused NTFS alternate data streams, a Windows file system feature that lets extra data hide behind a file’s name. Inside a RAR archive, those streams carried relative paths that climbed out of the extraction folder. When a user opened the archive and extracted what appeared to be a single harmless document, WinRAR also wrote hidden files to other locations on disk.

The favored destination was the user’s Startup folder. A file dropped there, such as a malicious shortcut or DLL loader, executes automatically at the next logon. The attackers even padded archives with dummy entries so that any warnings WinRAR displayed were buried in a long list the user was unlikely to scroll through.

ESET reported the flaw to RARLAB, WinRAR’s developer, and a fix shipped in WinRAR 7.13 on July 30, 2025. The vulnerable code was also present in the Windows versions of UnRAR, UnRAR.dll and the portable UnRAR source code, which means other applications that bundle those components needed updates too. It followed a similar WinRAR directory traversal bug, CVE-2025-6218, fixed a month earlier in version 7.12.

Who exploited it and how

ESET attributed the first campaign to RomCom, a Russia-aligned group that runs both espionage and financially motivated operations. Between July 18 and 21, 2025, RomCom sent spearphishing emails with RAR files disguised as job application CVs to financial, manufacturing, defense and logistics companies in Europe and Canada. Successful exploitation delivered backdoors including a Mythic agent, a SnipBot variant and a downloader called RustyClaw. ESET said its telemetry showed none of those particular targets were compromised, but the intent was clear.

RomCom was not alone. Russian security firm BI.ZONE independently reported a second group, tracked as Paper Werewolf, exploiting the same flaw against Russian organizations. Two unrelated actors using the same bug in the same weeks suggests the exploit was circulating in underground markets before disclosure.

The delivery method matters because it defeats common assumptions. The email carried a RAR file, not an executable. The visible content was an ordinary document. No macros were involved. A user did exactly what they do every day, opened an attachment from someone who appeared to be a job applicant, and the compromise happened as a side effect.

Why utility software is a blind spot

Most patch programs are built around the operating system and a handful of big applications: Windows, Office, browsers, maybe PDF readers. Utilities like archive tools, media players and small productivity apps fall outside that loop. They are often installed years ago, sometimes by users, and never touched again.

WinRAR illustrates the problem well. It has no automatic update mechanism, so every installation stays on whatever version was installed until someone deliberately replaces it. It is widely deployed and familiar enough that nobody questions it. And its job, processing untrusted files from email and the web, puts it directly on the attack path. That is what “legacy” really means in security: not old code, but software that is present, trusted and unmanaged.

What to do now

The immediate fix is simple; the durable fix is process. Work through both:

  1. Find every copy. Query your endpoint management or EDR inventory for WinRAR, and for other software that bundles UnRAR components. Include servers and jump boxes, not just laptops.
  2. Update to 7.13 or later, or remove it. Windows 11 now opens RAR files natively through its built-in archive support, and many organizations can standardize on one managed archive tool instead of several unmanaged ones.
  3. Hunt for signs of exploitation. Look for new or unusual files in user and system Startup folders, especially shortcuts and DLLs created around the time an archive was extracted, and for processes launched by WinRAR that are not WinRAR.
  4. Tighten email filtering for archives. Quarantine or sandbox RAR attachments from external senders, particularly to HR, recruiting and finance teams who routinely receive files from strangers.
  5. Brief your users. Explain that archive attachments from unknown senders should be treated like executables, and that a job application arriving as a RAR file is itself a red flag.
  6. Bring utilities into patch management. Add third-party software to your regular patch cycle, with an owner, a version baseline and a monitoring source for security advisories.

The trade-off is effort: third-party patching adds work and occasionally breaks a workflow. But compliance frameworks from PCI DSS to CMMC expect a complete software inventory and timely patching, and a vulnerability like this is exactly what they are meant to catch. Our cybersecurity and compliance services help build that inventory and patch process. For the broader pattern, see Critical Zero-Days: Legacy Software and Widely-Used Platforms Under Siege and Is Your Organization Prepared for Stricter Patch Deadlines?

Update (September 2026): Exploitation broadened well beyond the original zero-day campaigns. In January 2026, Google Threat Intelligence Group reported that CVE-2025-8088 was being used by several Russia-linked state groups, a China-based actor and multiple criminal operations, including groups delivering commodity remote access trojans and banking malware, all relying on the same Startup-folder technique. Unpatched WinRAR installations remain a live target.

Frequently asked questions

Which versions of WinRAR are affected by CVE-2025-8088?

WinRAR for Windows versions before 7.13, along with the Windows versions of UnRAR, UnRAR.dll and the portable UnRAR source code. WinRAR for Unix, RAR for Android and non-Windows UnRAR builds were not affected, according to RARLAB.

Will WinRAR update itself?

No. WinRAR does not include an automatic updater, so every installation must be updated manually or through your software deployment tool. This is a key reason vulnerable versions linger long after a fix is released.

How can we tell if we were compromised?

Check Startup folders for unexpected shortcuts, scripts or DLLs, review EDR telemetry for child processes spawned during archive extraction, and search mail logs for RAR attachments received around July and August 2025 and afterward. If you find indicators, treat the machine as compromised and investigate further.

Closing the utility software gap

Delana Technologies helps organizations inventory all installed software, bring third-party applications into patch management, and hunt for signs of exploitation when a zero-day like CVE-2025-8088 appears. To review your exposure, call 239.414.5126 or contact us.


Sources: ESET Research, “Update WinRAR tools now: RomCom and others exploiting zero-day vulnerability” (August 2025); RARLAB WinRAR 7.13 release notes (July 2025); BI.ZONE reporting on Paper Werewolf (August 2025); Google Threat Intelligence Group reporting on CVE-2025-8088 exploitation, via The Hacker News (January 2026).

Post navigation

Previous: Is Your Organization Prepared for Stricter Patch Deadlines?
Next: The Silent Threat: Proxy Botnets Are Hijacking VPS Servers for Covert Attacks

Florida Service Location

  • Cybersecurity, AI Consulting & IT Services in West Palm Beach, Florida
  • Cybersecurity, AI Consulting & IT Services in Sarasota, Florida
  • Cybersecurity, AI Consulting & IT Services in Port St. Lucie, Florida
  • Cybersecurity, AI Consulting & IT Services in Pembroke Pines, Florida
  • Cybersecurity, AI Consulting & IT Services in Naples, Florida
  • Cybersecurity, AI Consulting & IT Services in Miramar, Florida
  • Cybersecurity, AI Consulting & IT Services in Miami, Florida
  • Cybersecurity, AI Consulting & IT Services in Hollywood, Florida
  • Cybersecurity, AI Consulting & IT Services in Hialeah, Florida
  • Cybersecurity, AI Consulting & IT Services in Fort Myers, Florida
  • Cybersecurity, AI Consulting & IT Services in Fort Lauderdale, Florida
  • Cybersecurity, AI Consulting & IT Services in Cape Coral, Florida
  • Cybersecurity, AI Consulting & IT Services in Boca Raton, Florida
  • Cybersecurity, AI Consulting & IT Services in Coral Springs, Florida

Technology Services

  • Cybersecurity Compliance & Regulatory Framework Services
  • Workflow Automation & Systems Integration
  • Cloud Modernization & Technology Innovation Services
  • Fractional CTO & Expert Technical Consultants
  • Data Analytics, BI & Modern Data Platforms
  • Cyber Litigation Support & Digital Forensics
  • Cybersecurity Solutions & Zero Trust Architecture
  • AI Consulting & Agentic AI Solutions
  • Case Studies
  • Home
  • Contact Us
  • Privacy Policy
  • Cybersecurity Compliance & Regulatory Framework Services
  • Workflow Automation & Systems Integration
  • Cloud Modernization & Technology Innovation Services
  • Fractional CTO & Expert Technical Consultants
  • Data Analytics, BI & Modern Data Platforms
  • Cyber Litigation Support & Digital Forensics
  • Cybersecurity Solutions & Zero Trust Architecture
  • AI Consulting & Agentic AI Solutions

© Copyright 2025 Delana Technologies LLC