{"id":1230,"date":"2026-06-09T13:37:04","date_gmt":"2026-06-09T13:37:04","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=1230"},"modified":"2026-06-09T13:37:04","modified_gmt":"2026-06-09T13:37:04","slug":"winrar-flaw-exploited-by-russia-aligned-groups-to-deploy-stealers-in-ukraine","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=1230","title":{"rendered":"WinRAR Flaw Exploited by Russia-Aligned Groups to Deploy Stealers in Ukraine"},"content":{"rendered":"<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Ravie Lakshmanan<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">Jun 09, 2026<\/span><\/span><span class=\"p-tags\">Vulnerability \/ Cyber Espionage<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhpdAzGyUad4rioCXpoCvPwiGqto_MgCesTBLTn-1uBtWpWAXB99KN0xiE1oIqwDbVi_vkFDnn05XOxwH3WYjLkPNDykxieuftfe-wLFibGL1o8iiUuGfhiG5yYS7KXBV3gvdIYk5PFCurpn0-L77hajka35iE_a-JxWCaYeKc2Yej1gQrkcrQ61ijTm4HS\/s1700-e365\/winrar-exploit.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>Two Russia-aligned cyber attack campaigns have continued to exploit a security flaw in WinRAR to target Ukrainian organisations, almost a year after patches for the vulnerability were released.<\/p>\n<p>The activity has been attributed by Trend Micro to Earth Dahu (aka Gamaredon) and SHADOW-EARTH-066 (aka UAC-0226). It involves the exploitation of CVE-2025-8088, a path traversal flaw that allows an attacker to write files outside the extraction directory via NTFS Alternate Data Streams (ADS). It was patched by WinRAR in July 2025.<\/p>\n<p>The findings show \u00abhow unmanaged software keeps an exploited entry point open long after the fix ships,\u00bb Trend Micro researchers Hiroyuki Kakara and Feike Hacquebord <a href=\"https:\/\/www.trendmicro.com\/en_us\/research\/26\/f\/old-winrar-flaw-fuels-attacks-on-ukraine.html\">said<\/a> in an analysis published Monday.<\/p>\n<p>The WinRAR exploit chain exploited by SHADOW-EARTH-066 is a departure from Excel macro droppers previously used by the threat actor to deliver an information stealer called GIFTEDCROOK. The latest iteration makes use of crafted RAR archives featuring a decoy PDF document and three hidden ADS payloads that are outside the extraction directory to initiate the infection.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/ai-cant-stop-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjPEV6-530TOlxG6PjrmdlY623wpBwduZ7t1HV6flcmO5R4q4AmfixDUzW0CrhlvMVNWbhvOIso-UDNTka4W_W9Chrdj_dglwBZwi7DuePM2IMIl-hfUYVIqBXgfpr_2619K8Gptb4LzwJ6gUbi7lWl2M8AFQJsHEaw63Q7tZ6708YGruiHrr0Y2W9YYxLQ\/s728-e100\/ThreatLocker-d.png\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>This includes a Windows Shortcut (LNK) file that&#8217;s placed in the Startup folder so that it&#8217;s automatically executed every time a user logs in. This, in turn, spawns a PowerShell loader via \u00abcmd.exe,\u00bb which then uses in-memory DLL loading to ultimately launch an updated version of GIFTEDCROOK (\u00abresult.dll\u00bb).<\/p>\n<p><a name=\"more\"\/><\/p>\n<p>The malware targets passwords and cookies from Chromium-based browsers (Google Chrome, Microsoft Edge, and Opera) and Mozilla Firefox, in addition to harvesting documents matching certain extensions from the victim&#8217;s machine. Once the data is exfiltrated to an external server, all malicious artifacts are deleted to cover up the forensic trail.<\/p>\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgEtOp_HjW6WhHu0Cvwcicr9nXJFdNNrwkQEGUY6C2Tz_PvMjUaDLEDot6QWr5e-a4EG4c3SOMtz1zAcsJaXgRj2SAbAwyr1QMNKAEanfuyqBsR-1UJqDG18YFt6gtaukZiVYCCMVhlLHEoew7tk0_RTiNxIiIOztQ8aNJ-ZtNMzwVXBsboqbGXYA8-1yVT\/s1700-e365\/winrar.png\" style=\"display: block;  text-align: center; clear: left; float: left;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgEtOp_HjW6WhHu0Cvwcicr9nXJFdNNrwkQEGUY6C2Tz_PvMjUaDLEDot6QWr5e-a4EG4c3SOMtz1zAcsJaXgRj2SAbAwyr1QMNKAEanfuyqBsR-1UJqDG18YFt6gtaukZiVYCCMVhlLHEoew7tk0_RTiNxIiIOztQ8aNJ-ZtNMzwVXBsboqbGXYA8-1yVT\/s1700-e365\/winrar.png\" alt=\"\" border=\"0\" data-original-height=\"916\" data-original-width=\"1340\"\/><\/a><\/div>\n<p>A notable change is the shift from Telegram as an exfiltration channel to dedicated command-and-control (C2) servers, a key modification that likely aligns with Russia&#8217;s blocking of the messaging platform in the country earlier this February.<\/p>\n<p>The second Russia-affiliated hacking group to weaponize CVE-2025-8088 is Earth Dahu, which has incorporated the flaw into its arsenal since at least September 2025. The adversary is known for its \u00abindustrial-scale effort\u00bb to maintain long-term access to compromised organizations.<\/p>\n<p>\u00abEarth Dahu used the vulnerability with an HTA-to-VBScript infection chain that delivered espionage modules,\u00bb Trend Micro noted. \u00abBased on RAR internal file timestamps and file naming conventions, the chain remained active through at least April 10, 2026.\u00bb<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/vpn-threat-report-m\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhFlTC7RrRZGiFAgASS0noWSL0qsQGFVp8-Hvuw9yp3X3VKRuTcb5SsPX09wJzrdIM6pu1_5lS4EeZp7Sx4iYBpNJkrGnpr08yyaS1HQ5_5TxaCsP6O0OtHNuOkesn6CbNjao1GPulCJk-uljYMSfMZfBYNrngpe669t7jlRn1FqiEnXhsFD1WVkpaYIVgh\/s728-e100\/ai-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>These attacks, as recently also documented by Sekoia last week, lead to the deployment of GammaPhish, an HTML Application (HTA), which is then used to retrieve a VBScript downloader named GammaLoad. The intermediate downloader subsequently delivers additional modules like GammaSteel.<\/p>\n<p>GammaLoad is \u00aba collection of VBScripts designed to ensure continuous access and deploy payloads over time by leveraging Dead Drop Resolvers (DDR),\u00bb Sekoia <a href=\"https:\/\/blog.sekoia.io\/fsbs-matryoshka-2-3-gamaredons-gifts-that-keeps-unpacking-gammaload\/\">said<\/a>, adding it&#8217;s used to deploy a dropper that&#8217;s designed to launch a VBScript loader responsible for executing <a href=\"https:\/\/blog.sekoia.io\/fsbs-matryoshka-3-3-gamaredons-gifts-that-keeps-unpacking-gammasteel\/\">GammaSteel<\/a>, a comprehensive information stealer that can monitor changes to files in real-time.<\/p>\n<p>\u00abWinRAR is deeply embedded in daily operations across Ukrainian organizations, making it an attractive target for exploitation,\u00bb Trend Micro said. \u00abThe convergence of both established state-backed groups and independently tracked clusters on a single vulnerability reflects the scale of the cyber threats that Ukraine faces.\u00bb<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\ue804Ravie Lakshmanan\ue802Jun 09, 2026Vulnerability \/ Cyber Espionage Two Russia-aligned cyber attack campaigns have continued to exploit a security flaw in WinRAR to target Ukrainian organisations, almost a year after patches&hellip;<\/p>\n","protected":false},"author":1,"featured_media":1231,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[229,128,70,1499,1970,1971,451,185],"class_list":["post-1230","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-deploy","tag-exploited","tag-flaw","tag-groups","tag-russiaaligned","tag-stealers","tag-ukraine","tag-winrar"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/1230","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1230"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/1230\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/1231"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1230"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1230"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1230"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}