Close Menu
    What's Hot

    Titan Machinery Inc. (TITN) Q1 2027 Earnings Call Transcript

    Argentina to avoid ‘risks’ with Messi set to play in friendly

    England’s World Cup chances assessed as they are rated third favourites behind Spain and France – Between the Lines | Football News

    Facebook X (Twitter) Instagram
    Trending
    • Titan Machinery Inc. (TITN) Q1 2027 Earnings Call Transcript
    • Argentina to avoid ‘risks’ with Messi set to play in friendly
    • England’s World Cup chances assessed as they are rated third favourites behind Spain and France – Between the Lines | Football News
    • Wembanyama, Spurs stun Knicks at MSG to revive Finals hopes
    • Rivian R2 2026: Specs, Price, Availability
    • Researchers Build Self-Replicating AI Worm That Operates Entirely on Local, Open-Weight Models
    • Artemis III Astronauts to Wear Prada Spacesuits
    • What do you need to unlearn at work?
    interluknewsinterluknews
    • Home
    • Business
      • Corporate News
      • Industry Insights
      • Startups & Entrepreneurship
      • Technology & Innovation
    • Economy
      • Economic Policy
      • Financial Analysis
      • Inflation & Interest Rates
      • Trade & Markets
    • Global
      • Conflicts & Security
      • Diplomacy
      • Global Trends
      • International Affairs
    • Lifestyle
      • Fashion
      • Food & Dining
      • Personal Development
      • Travel
    • Opinion
      • Columns
      • Editorials
      • Expert Opinions
      • Reader Voices
    • More
      • Politics
        • Elections
        • Government & Policy
        • International Relations
        • Political Analysis
      • Sports
        • Cricket
        • Football / Soccer
        • International Sports
        • Local Sports
      • Technology
        • Artificial Intelligence
        • Cybersecurity
        • Gadgets & Reviews
        • Tech News
      • South Africa News
    Facebook X (Twitter) Instagram
    interluknewsinterluknews
    Cybersecurity

    WinRAR Flaw Exploited by Russia-Aligned Groups to Deploy Stealers in Ukraine

    adminBy adminJune 9, 2026No Comments3 Mins Read
    Share Facebook Twitter Pinterest Copy Link Telegram LinkedIn Tumblr Email
    WinRAR Flaw Exploited by Russia-Aligned Groups to Deploy Stealers in Ukraine
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananJun 09, 2026Vulnerability / Cyber Espionage

    WinRAR Flaw Exploited by Russia-Aligned Groups to Deploy Stealers in Ukraine

    Two Russia-aligned cyber attack campaigns have continued to exploit a security flaw in WinRAR to target Ukrainian organisations, almost a year after patches for the vulnerability were released.

    The activity has been attributed by Trend Micro to Earth Dahu (aka Gamaredon) and SHADOW-EARTH-066 (aka UAC-0226). It involves the exploitation of CVE-2025-8088, a path traversal flaw that allows an attacker to write files outside the extraction directory via NTFS Alternate Data Streams (ADS). It was patched by WinRAR in July 2025.

    The findings show “how unmanaged software keeps an exploited entry point open long after the fix ships,” Trend Micro researchers Hiroyuki Kakara and Feike Hacquebord said in an analysis published Monday.

    The WinRAR exploit chain exploited by SHADOW-EARTH-066 is a departure from Excel macro droppers previously used by the threat actor to deliver an information stealer called GIFTEDCROOK. The latest iteration makes use of crafted RAR archives featuring a decoy PDF document and three hidden ADS payloads that are outside the extraction directory to initiate the infection.

    Cybersecurity

    This includes a Windows Shortcut (LNK) file that’s placed in the Startup folder so that it’s automatically executed every time a user logs in. This, in turn, spawns a PowerShell loader via “cmd.exe,” which then uses in-memory DLL loading to ultimately launch an updated version of GIFTEDCROOK (“result.dll”).

    The malware targets passwords and cookies from Chromium-based browsers (Google Chrome, Microsoft Edge, and Opera) and Mozilla Firefox, in addition to harvesting documents matching certain extensions from the victim’s machine. Once the data is exfiltrated to an external server, all malicious artifacts are deleted to cover up the forensic trail.

    A notable change is the shift from Telegram as an exfiltration channel to dedicated command-and-control (C2) servers, a key modification that likely aligns with Russia’s blocking of the messaging platform in the country earlier this February.

    The second Russia-affiliated hacking group to weaponize CVE-2025-8088 is Earth Dahu, which has incorporated the flaw into its arsenal since at least September 2025. The adversary is known for its “industrial-scale effort” to maintain long-term access to compromised organizations.

    “Earth Dahu used the vulnerability with an HTA-to-VBScript infection chain that delivered espionage modules,” Trend Micro noted. “Based on RAR internal file timestamps and file naming conventions, the chain remained active through at least April 10, 2026.”

    Cybersecurity

    These attacks, as recently also documented by Sekoia last week, lead to the deployment of GammaPhish, an HTML Application (HTA), which is then used to retrieve a VBScript downloader named GammaLoad. The intermediate downloader subsequently delivers additional modules like GammaSteel.

    GammaLoad is “a collection of VBScripts designed to ensure continuous access and deploy payloads over time by leveraging Dead Drop Resolvers (DDR),” Sekoia said, adding it’s used to deploy a dropper that’s designed to launch a VBScript loader responsible for executing GammaSteel, a comprehensive information stealer that can monitor changes to files in real-time.

    “WinRAR is deeply embedded in daily operations across Ukrainian organizations, making it an attractive target for exploitation,” Trend Micro said. “The convergence of both established state-backed groups and independently tracked clusters on a single vulnerability reflects the scale of the cyber threats that Ukraine faces.”

    deploy Exploited flaw groups RussiaAligned Stealers Ukraine WinRAR
    Follow on Google News Follow on Flipboard
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
    Previous ArticleWhy you need to stop using passwords and switch to this secure alternative now
    Next Article Nintendo Direct June 2026: All the news and trailers
    admin
    • Website

    Related Posts

    Researchers Build Self-Replicating AI Worm That Operates Entirely on Local, Open-Weight Models

    June 9, 2026

    The Hidden Security Risk in Modern Networks: The Work Between Tools

    June 9, 2026

    LiteLLM Flaw CVE-2026-42271 Exploited in the Wild, Chains to Unauthenticated RCE

    June 9, 2026
    Leave A Reply Cancel Reply

    Demo
    Latest Posts

    Titan Machinery Inc. (TITN) Q1 2027 Earnings Call Transcript

    Argentina to avoid ‘risks’ with Messi set to play in friendly

    England’s World Cup chances assessed as they are rated third favourites behind Spain and France – Between the Lines | Football News

    Wembanyama, Spurs stun Knicks at MSG to revive Finals hopes

    Latest Posts

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    Advertisement
    Demo

    We are a digital news platform delivering timely, accurate, and insightful coverage of politics, global affairs, business, economy, sports, and more. Our mission is to keep readers informed with reliable news, clear analysis, and stories that truly matter.
    We're social. Connect with us:

    Facebook X (Twitter) Instagram Pinterest YouTube

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.

    Powered by
    ...
    ►
    Necessary cookies enable essential site features like secure log-ins and consent preference adjustments. They do not store personal data.
    None
    ►
    Functional cookies support features like content sharing on social media, collecting feedback, and enabling third-party tools.
    None
    ►
    Analytical cookies track visitor interactions, providing insights on metrics like visitor count, bounce rate, and traffic sources.
    None
    ►
    Advertisement cookies deliver personalized ads based on your previous visits and analyze the effectiveness of ad campaigns.
    None
    ►
    Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
    None
    Powered by