{"id":1077,"date":"2026-06-11T15:18:28","date_gmt":"2026-06-11T09:48:28","guid":{"rendered":"https:\/\/www.hexnode.com\/threat-watch\/?p=1077"},"modified":"2026-08-19T15:25:34","modified_gmt":"2026-08-19T09:55:34","slug":"winrar-vulnerability-cve-2025-8088-ukraine","status":"publish","type":"post","link":"https:\/\/www.hexnode.com\/threat-watch\/winrar-vulnerability-cve-2025-8088-ukraine\/","title":{"rendered":"WinRAR Vulnerability CVE-2025-8088 Exploited Against Ukrainian Organizations"},"content":{"rendered":"<h2>A Patched WinRAR Flaw Is Still Being Used in Active Espionage Campaigns<\/h2>\n<p>The continued exploitation of the WinRAR Vulnerability CVE-2025-8088 demonstrates a recurring challenge in enterprise security: software may be patched, yet remain vulnerable across large numbers of endpoints because updates are not consistently deployed.<\/p>\n<p>In recently observed campaigns targeting Ukrainian organizations, two Russia-aligned threat clusters reportedly leveraged the flaw to deliver different malware families designed for intelligence collection and espionage operations. The attacks relied on phishing emails containing weaponized archive files.<\/p>\n<p>The campaigns are notable not because they exploited a previously unknown vulnerability, but because they successfully leveraged a known and patched weakness in a widely used desktop utility. This reinforces the reality that attackers often prefer reliable, proven techniques when organizations fail to close known security gaps.<\/p>\n<p><center>    \t\t<!-- button style scb20be917a3efc78059cf9961ee4e54284 -->\r\n    \t\t<style>\r\n    \t\t\t.scb20be917a3efc78059cf9961ee4e54284, a.scb20be917a3efc78059cf9961ee4e54284{\r\n    \t\t\t\tcolor: #fff;\r\n    \t\t\t\tbackground-color: #00868B;\r\n    \t\t\t}\r\n    \t\t\t.scb20be917a3efc78059cf9961ee4e54284:hover, a.scb20be917a3efc78059cf9961ee4e54284:hover{\r\n    \t\t\t\t    \t\t\t\tbackground-color: #32b8bd;\r\n    \t\t\t}\r\n    \t\t<\/style>\r\n    \t\t<a href=\"https:\/\/www.hexnode.com\/uem\/features\/patch-and-update-management\/\" class=\"ht-shortcodes-button scb20be917a3efc78059cf9961ee4e54284  hn-cta__blogs--inline-button \" id=\"\" style=\"\" target=\"_blank\">\r\n    \t\tImprove Patch Compliance Across Endpoints<\/a>\r\n    \t\t<\/center><\/p>\n<h2>How the WinRAR Vulnerability CVE-2025-8088 Works<\/h2>\n<p>The WinRAR Vulnerability CVE-2025-8088 is a path traversal flaw affecting vulnerable versions of WinRAR for Windows. The flaw allows specially crafted archive files to write content outside the directory selected by the user during extraction. This behavior can enable attackers to place files into sensitive system locations, including Windows Startup folders.<\/p>\n<p>When files are written into Startup locations, payloads may execute automatically the next time a user logs in, providing attackers with a mechanism for persistence and malware delivery. Multiple threat actors have reportedly adopted this technique since the vulnerability became publicly known and patched.<\/p>\n<p>A typical attack chain observed in campaigns exploiting the vulnerability follows a straightforward pattern:<\/p>\n<ol>\n<li>A <a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-is-phishing\/\">phishing<\/a> email delivers a malicious archive.<\/li>\n<li>The user extracts the archive using a vulnerable WinRAR version.<\/li>\n<li>The archive writes malicious files outside the intended extraction path.<\/li>\n<li>Malware is placed in Startup directories or other targeted locations.<\/li>\n<li>Payloads execute after login and begin follow-on activity.<\/li>\n<\/ol>\n<p>Because the attack relies on user interaction and outdated software, organizations that lack visibility into third-party application versions may remain exposed even when operating systems are fully patched.<\/p>\n<h2>How Russian-Aligned Threat Groups Exploited CVE-2025-8088<\/h2>\n<p>The campaigns attributed to Shadow-Earth-066 (UAC-0226) and Earth Dahu (Gamaredon\/UAC-0010) used the same underlying vulnerability but delivered different payloads and post-exploitation activity.<\/p>\n<h3>Shadow-Earth-066 Uses GiftedCrook Malware<\/h3>\n<p>Shadow-Earth-066 reportedly exploited CVE-2025-8088 to deploy an updated version of GiftedCrook, an information-stealing <a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-is-a-malware-family\/\">malware family<\/a>.<\/p>\n<p>Public reporting indicates that GiftedCrook is capable of collecting credentials, browser-stored passwords, session cookies, documents, and files matching attacker-defined extensions. The malware has also been observed deleting itself after completing its collection activities, which may complicate forensic analysis.<\/p>\n<p>While the malware&#8217;s capabilities are documented, public reporting has not confirmed the extent of any data collection or exfiltration resulting from these specific campaigns.<\/p>\n<h3>Earth Dahu (Gamaredon) Deploys HTA-Based Malware<\/h3>\n<p>A separate campaign attributed to Earth Dahu, also known as Gamaredon, reportedly used malicious archives to initiate an espionage-focused infection chain.<\/p>\n<p>The observed activity involved HTML Application (HTA) files, VBScript components, and infrastructure hosted through Cloudflare Workers to retrieve additional payloads. Similar <a href=\"https:\/\/attack.mitre.org\/groups\/G0047\/?utm_source=hexnode_blog&amp;utm_medium=referral&amp;utm_campaign=winrar_vulnerability_cve_2025_8088\" target=\"_blank\" rel=\"nofollow noreferrer noopener\">Gamaredon campaigns<\/a> observed during 2026 involved an HTA payload and VBScript downloader chain.<\/p>\n<p>Although the malware families differed, both campaigns shared a common dependency: vulnerable WinRAR installations and user interaction with malicious archive files.<\/p>\n<div class=\"next_blog\"><div class=\"post-next\"><div class=\"hex_blog_box_parent\"><div class=\"blog_warp_next\"><div class=\"next_blog_thumb\" style=\"background-image:url(https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/IT-admins-guide-to-patch-management-with-hexnode-150x150-1.webp?format=webp)\"><\/div><div class=\"next_post_content\"><div class=\"center_box\"><h4>IT Admin\u2019s Guide to Patch Management with Hexnode<\/h4><p>Learn how to streamline patch deployment, and reduce security risks across managed endpoints with Hexnode.<\/p><\/div><\/div><\/div><a class=\"hex_blog_box_link hn-cta__blogs--blog-box\" href=\"https:\/\/www.hexnode.com\/blogs\/it-admins-guide-to-patch-management-with-hexnode\/\" aria-label=\"IT Admin\u2019s Guide to Patch Management with Hexnode\"><\/a><\/div><\/div><\/div>\n<h2>Why the WinRAR Vulnerability CVE-2025-8088 Matters to Enterprises<\/h2>\n<p>The most significant lesson from this activity is not the vulnerability itself. It is the operational gap that allowed exploitation to continue long after a patch became available.<\/p>\n<p>The ongoing exploitation of the WinRAR Vulnerability CVE-2025-8088 also highlights the risks posed by unmanaged third-party applications that fall outside standard update processes.<\/p>\n<p>Many organizations maintain mature operating system patching programs but have less visibility into utilities installed directly by users or departmental teams. Archive managers, PDF tools, media utilities, and other desktop applications can easily fall outside standard update workflows.<\/p>\n<p>WinRAR presents a particularly relevant example because it does not automatically update itself. Systems can therefore remain vulnerable for extended periods unless administrators actively verify version compliance and deploy updates.<\/p>\n<p>For organizations handling sensitive information, including government agencies, defense contractors, financial institutions, legal teams, and critical infrastructure operators, these unmanaged applications can become attractive entry points for attackers.<\/p>\n<p>The campaigns also reinforce several broader security realities:<\/p>\n<ul>\n<li>Known vulnerabilities continue to be widely exploited in real-world campaigns.<\/li>\n<li>Phishing remains an effective initial access technique.<\/li>\n<li>User-installed software can create security blind spots.<\/li>\n<li>Persistence mechanisms often rely on legitimate Windows functionality.<\/li>\n<li>Endpoint visibility can help identify suspicious execution chains.<\/li>\n<\/ul>\n<h2>Reducing Risk from the WinRAR Vulnerability CVE-2025-8088 with Hexnode<\/h2>\n<p>Organizations seeking to reduce the risks associated with the WinRAR Vulnerability CVE-2025-8088 should focus on application visibility, patch governance, and endpoint monitoring.<\/p>\n<h3>Using Hexnode UEM for Application Visibility and Patch Compliance<\/h3>\n<p><a href=\"https:\/\/www.hexnode.com\/uem\/\">Hexnode UEM<\/a> can help organizations:<\/p>\n<ul>\n<li>Maintain inventory visibility across managed devices.<\/li>\n<li>Identify installed application versions.<\/li>\n<li>Enforce application management policies.<\/li>\n<li>Deploy approved software versions.<\/li>\n<li>Support <a href=\"https:\/\/www.hexnode.com\/uem\/platform\/windows-mdm\/\">Windows<\/a> app patch management efforts.<\/li>\n<li>Remove or restrict unauthorized applications where appropriate.<\/li>\n<\/ul>\n<p>These capabilities can help security and IT teams review managed application inventory and enforce app update policies on supported Windows devices.<\/p>\n<h3>Using Hexnode XDR for Endpoint Investigation and Response<\/h3>\n<p>If suspicious activity occurs on an endpoint, <a href=\"https:\/\/www.hexnode.com\/xdr\/\">Hexnode XDR<\/a> can help security teams:<\/p>\n<ul>\n<li>Investigate suspicious endpoint activity.<\/li>\n<li>Hunt threats using endpoint data and investigation queries.<\/li>\n<li>Isolate affected endpoints when necessary.<\/li>\n<li>Terminate malicious processes during response efforts.<\/li>\n<li>Support endpoint investigation and response workflows.<\/li>\n<\/ul>\n<p>These capabilities can assist responders in understanding how activity unfolded on an endpoint and support containment actions during an investigation.<\/p>\n<h3>Strengthening Access Controls with Hexnode IdP<\/h3>\n<p>Organizations can further strengthen access controls through:<\/p>\n<ul>\n<li>Multi-factor authentication (MFA).<\/li>\n<li>Role-based access control (RBAC).<\/li>\n<li>Device compliance validation integrated with managed endpoints.<\/li>\n<li>Microsoft Entra ID integration.<\/li>\n<li>Conditional access rules based on user identity, device compliance, and security context.<\/li>\n<\/ul>\n<p>While identity controls do not prevent attackers from exploiting CVE-2025-8088, they can strengthen access controls if attackers target credentials in follow-on activity.<\/p>\n<section id='resource-single'>\n                    <div class='resource-box'>\n                        <div class='resource-box__image-section'>\n                            <div class='resource-box__image-wrap'>\n                                <img decoding=\"async\" src=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-app-management-solution-300x225-1.webp?format=webp\" class=\"resource-box__image\" alt=\"Hexnode App Management Solution\" loading=\"lazy\" srcset=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-app-management-solution-300x225-1.webp?format=webp 300w, https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-app-management-solution-300x225-1-133x100.webp?format=webp 133w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" title=\"hexnode-app-management-solution--300x225\" \/>\n                            <\/div>\n                        <\/div>\n                        <div class='resource-box__content-section'>\n                            <h5 class='resource-box__content-subheading'>\n                            Featured resource\n                            <\/h5>\n                            <h4 class='resource-box__content-heading'>\n                            Hexnode App Management Solution\n                            <\/h4>\n                            <p class='resource-box__contents'>\n                            Learn how Hexnode helps IT teams streamline application deployment, management, and updates across devices from a centralized platform.\n                            <\/p>\n                            <a class='resource-box__content-link hn-cta__blogs--resource-box' href='https:\/\/www.hexnode.com\/resources\/datasheets\/hexnode-app-management-solution\/'>\n                            Download the Datasheet\n                            <svg xmlns='http:\/\/www.w3.org\/2000\/svg' width='20' height='20' viewBox='0 0 20 20'>\n                            <g id='arrow' transform='translate(-309 -191)' opacity='0'>\n                                <rect id='base' width='20' height='20' transform='translate(309 191)' fill='none'\/>\n                                <path id='arrow-2' data-name='arrow' d='M13.093.5,6.8,6.8.5.5' transform='translate(315 207.594) rotate(-90)' fill='none' stroke='#0549d1' stroke-linecap='round' stroke-linejoin='round' stroke-width='1.2'\/>\n                            <\/g>\n                            <\/svg>\n\n                            <\/a>\n                        <\/div>\n                    <\/div>\n                <\/section>\n<h2>Key Lessons from the WinRAR Vulnerability CVE-2025-8088 Campaigns<\/h2>\n<p>The renewed exploitation of the WinRAR Vulnerability CVE-2025-8088 serves as a reminder that endpoint risk often hides in overlooked software rather than unpatched operating systems.<\/p>\n<p>The campaigns targeting Ukrainian organizations demonstrate how threat actors continue to capitalize on known vulnerabilities when patch adoption lags behind disclosure and remediation timelines. A single outdated utility can provide attackers with a reliable path to malware delivery, persistence, and potential intelligence collection.<\/p>\n<p>Reducing this risk requires more than patch availability. Organizations need continuous software inventory, application governance, phishing resilience, endpoint monitoring, and verification that they have actually applied updates across the environment.<\/p>\n<p>As attackers continue to weaponize known flaws, maintaining visibility into every application running on enterprise endpoints remains a critical part of modern security operations.<br \/>\n<div class=\"signup_box\"><div class=\"signup_wrap_img\"><div class=\"signup-bg\" style=\"background-image:url(https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Hexnode-MDM-free-trial.jpg?format=webp)\"><\/div><\/div><div class=\"signup_wrap\"><h5>Stay Ahead of Endpoint Vulnerabilities<\/h5><p>Gain visibility into installed applications, enforce update policies, and strengthen endpoint security with Hexnode.<\/p><a href=\"https:\/\/www.hexnode.com\/mobile-device-management\/cloud\/signup\/\" class=\"hn-cta__blogs--signup-stripe\" target=\"_blank\"> Sign up now<\/a><\/div><\/div><\/p>\n","protected":false},"excerpt":{"rendered":"<p>A Patched WinRAR Flaw Is Still Being Used in Active Espionage Campaigns The continued exploitation&#8230;<\/p>\n","protected":false},"author":4,"featured_media":1079,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[13,21],"class_list":["post-1077","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-identity-abuse","category-patch-management","product_category-unified-endpoint-management","tab_group-vulnerabilities"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>WinRAR Vulnerability CVE-2025-8088 Exploited in Ukraine<\/title>\n<meta name=\"description\" content=\"Russia-aligned groups are exploiting the WinRAR vulnerability CVE-2025-8088 against Ukrainian organizations using weaponized archives.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.hexnode.com\/threat-watch\/winrar-vulnerability-cve-2025-8088-ukraine\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"WinRAR Vulnerability CVE-2025-8088 Exploited in Ukraine\" \/>\n<meta property=\"og:description\" content=\"Russia-aligned groups are exploiting the WinRAR vulnerability CVE-2025-8088 against Ukrainian organizations using weaponized archives.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.hexnode.com\/threat-watch\/winrar-vulnerability-cve-2025-8088-ukraine\/\" \/>\n<meta property=\"og:site_name\" content=\"Hexnode Threat Watch\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Hexnode\/\" \/>\n<meta property=\"article:published_time\" content=\"2026-06-11T09:48:28+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-08-19T09:55:34+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/WinRAR-Vulnerability-CVE-2025-8088.jpeg?format=webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1500\" \/>\n\t<meta property=\"og:image:height\" content=\"844\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Nora Blake\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:site\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Nora Blake\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"1 minute\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":[\"Article\",\"BlogPosting\"],\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/winrar-vulnerability-cve-2025-8088-ukraine\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/winrar-vulnerability-cve-2025-8088-ukraine\\\/\"},\"author\":{\"name\":\"Nora Blake\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/0c83856887182474458e211729d39f9d\"},\"headline\":\"WinRAR Vulnerability CVE-2025-8088 Exploited Against Ukrainian Organizations\",\"datePublished\":\"2026-06-11T09:48:28+00:00\",\"dateModified\":\"2026-08-19T09:55:34+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/winrar-vulnerability-cve-2025-8088-ukraine\\\/\"},\"wordCount\":1128,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/winrar-vulnerability-cve-2025-8088-ukraine\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/WinRAR-Vulnerability-CVE-2025-8088.jpeg?format=webp\",\"articleSection\":[\"Identity Abuse\",\"Patch Management\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/winrar-vulnerability-cve-2025-8088-ukraine\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/winrar-vulnerability-cve-2025-8088-ukraine\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/winrar-vulnerability-cve-2025-8088-ukraine\\\/\",\"name\":\"WinRAR Vulnerability CVE-2025-8088 Exploited in Ukraine\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/winrar-vulnerability-cve-2025-8088-ukraine\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/winrar-vulnerability-cve-2025-8088-ukraine\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/WinRAR-Vulnerability-CVE-2025-8088.jpeg?format=webp\",\"datePublished\":\"2026-06-11T09:48:28+00:00\",\"dateModified\":\"2026-08-19T09:55:34+00:00\",\"description\":\"Russia-aligned groups are exploiting the WinRAR vulnerability CVE-2025-8088 against Ukrainian organizations using weaponized archives.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/winrar-vulnerability-cve-2025-8088-ukraine\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/winrar-vulnerability-cve-2025-8088-ukraine\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/winrar-vulnerability-cve-2025-8088-ukraine\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/WinRAR-Vulnerability-CVE-2025-8088.jpeg?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/WinRAR-Vulnerability-CVE-2025-8088.jpeg?format=webp\",\"width\":1500,\"height\":844,\"caption\":\"WinRAR Vulnerability CVE-2025-8088\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/winrar-vulnerability-cve-2025-8088-ukraine\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"WinRAR Vulnerability CVE-2025-8088 Exploited Against Ukrainian Organizations\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"name\":\"Hexnode Threat Watch\",\"description\":\"Latest cyber threats, smarter enterprise response.\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"alternateName\":\"Threat Watch\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\",\"name\":\"Hexnode\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"width\":100,\"height\":100,\"caption\":\"Hexnode\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/Hexnode\\\/\",\"https:\\\/\\\/x.com\\\/thehexnode\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/hexnode\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/0c83856887182474458e211729d39f9d\",\"name\":\"Nora Blake\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g\",\"caption\":\"Nora Blake\"},\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/author\\\/nora-blake\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"WinRAR Vulnerability CVE-2025-8088 Exploited in Ukraine","description":"Russia-aligned groups are exploiting the WinRAR vulnerability CVE-2025-8088 against Ukrainian organizations using weaponized archives.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.hexnode.com\/threat-watch\/winrar-vulnerability-cve-2025-8088-ukraine\/","og_locale":"en_US","og_type":"article","og_title":"WinRAR Vulnerability CVE-2025-8088 Exploited in Ukraine","og_description":"Russia-aligned groups are exploiting the WinRAR vulnerability CVE-2025-8088 against Ukrainian organizations using weaponized archives.","og_url":"https:\/\/www.hexnode.com\/threat-watch\/winrar-vulnerability-cve-2025-8088-ukraine\/","og_site_name":"Hexnode Threat Watch","article_publisher":"https:\/\/www.facebook.com\/Hexnode\/","article_published_time":"2026-06-11T09:48:28+00:00","article_modified_time":"2026-08-19T09:55:34+00:00","og_image":[{"width":1500,"height":844,"url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/WinRAR-Vulnerability-CVE-2025-8088.jpeg?format=webp","type":"image\/jpeg"}],"author":"Nora Blake","twitter_card":"summary_large_image","twitter_creator":"@thehexnode","twitter_site":"@thehexnode","twitter_misc":{"Written by":"Nora Blake","Est. reading time":"1 minute"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":["Article","BlogPosting"],"@id":"https:\/\/www.hexnode.com\/threat-watch\/winrar-vulnerability-cve-2025-8088-ukraine\/#article","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/winrar-vulnerability-cve-2025-8088-ukraine\/"},"author":{"name":"Nora Blake","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/0c83856887182474458e211729d39f9d"},"headline":"WinRAR Vulnerability CVE-2025-8088 Exploited Against Ukrainian Organizations","datePublished":"2026-06-11T09:48:28+00:00","dateModified":"2026-08-19T09:55:34+00:00","mainEntityOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/winrar-vulnerability-cve-2025-8088-ukraine\/"},"wordCount":1128,"commentCount":0,"publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/winrar-vulnerability-cve-2025-8088-ukraine\/#primaryimage"},"thumbnailUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/WinRAR-Vulnerability-CVE-2025-8088.jpeg?format=webp","articleSection":["Identity Abuse","Patch Management"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.hexnode.com\/threat-watch\/winrar-vulnerability-cve-2025-8088-ukraine\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.hexnode.com\/threat-watch\/winrar-vulnerability-cve-2025-8088-ukraine\/","url":"https:\/\/www.hexnode.com\/threat-watch\/winrar-vulnerability-cve-2025-8088-ukraine\/","name":"WinRAR Vulnerability CVE-2025-8088 Exploited in Ukraine","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/winrar-vulnerability-cve-2025-8088-ukraine\/#primaryimage"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/winrar-vulnerability-cve-2025-8088-ukraine\/#primaryimage"},"thumbnailUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/WinRAR-Vulnerability-CVE-2025-8088.jpeg?format=webp","datePublished":"2026-06-11T09:48:28+00:00","dateModified":"2026-08-19T09:55:34+00:00","description":"Russia-aligned groups are exploiting the WinRAR vulnerability CVE-2025-8088 against Ukrainian organizations using weaponized archives.","breadcrumb":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/winrar-vulnerability-cve-2025-8088-ukraine\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.hexnode.com\/threat-watch\/winrar-vulnerability-cve-2025-8088-ukraine\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/winrar-vulnerability-cve-2025-8088-ukraine\/#primaryimage","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/WinRAR-Vulnerability-CVE-2025-8088.jpeg?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/WinRAR-Vulnerability-CVE-2025-8088.jpeg?format=webp","width":1500,"height":844,"caption":"WinRAR Vulnerability CVE-2025-8088"},{"@type":"BreadcrumbList","@id":"https:\/\/www.hexnode.com\/threat-watch\/winrar-vulnerability-cve-2025-8088-ukraine\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.hexnode.com\/threat-watch\/"},{"@type":"ListItem","position":2,"name":"WinRAR Vulnerability CVE-2025-8088 Exploited Against Ukrainian Organizations"}]},{"@type":"WebSite","@id":"https:\/\/www.hexnode.com\/threat-watch\/#website","url":"https:\/\/www.hexnode.com\/threat-watch\/","name":"Hexnode Threat Watch","description":"Latest cyber threats, smarter enterprise response.","publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"alternateName":"Threat Watch","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.hexnode.com\/threat-watch\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization","name":"Hexnode","url":"https:\/\/www.hexnode.com\/threat-watch\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","width":100,"height":100,"caption":"Hexnode"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/Hexnode\/","https:\/\/x.com\/thehexnode","https:\/\/www.linkedin.com\/company\/hexnode"]},{"@type":"Person","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/0c83856887182474458e211729d39f9d","name":"Nora Blake","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g","caption":"Nora Blake"},"url":"https:\/\/www.hexnode.com\/threat-watch\/author\/nora-blake\/"}]}},"_links":{"self":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1077","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/comments?post=1077"}],"version-history":[{"count":1,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1077\/revisions"}],"predecessor-version":[{"id":1080,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1077\/revisions\/1080"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media\/1079"}],"wp:attachment":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media?parent=1077"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/categories?post=1077"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}