Close Menu
    What's Hot

    Apple’s App Store rolls out personalized recommendations

    Trump says in ‘final throes’ of peace deal but at least 8 killed in Lebanon | Benjamin Netanyahu News

    Golden Analytics lands $14M seed extension and opens AI platform to public beta – GeekWire

    Facebook X (Twitter) Instagram
    Trending
    • Apple’s App Store rolls out personalized recommendations
    • Trump says in ‘final throes’ of peace deal but at least 8 killed in Lebanon | Benjamin Netanyahu News
    • Golden Analytics lands $14M seed extension and opens AI platform to public beta – GeekWire
    • Sandstone raises $30M to bring AI to in-house legal teams
    • Why Apple’s A.I. Upgrade for Siri Won’t Be Available in Europe
    • Maggie Alphonsi: RFU council member resigns over discriminatory comments about World Cup winner | Rugby Union News
    • Queen’s Club: Emma Raducanu impresses in blistering straight sets win over Anna Blinkova in lead up to Wimbledon | Tennis News
    • Ranking 15 NFL QBs whose legacy would change most with a Super Bowl win
    interluknewsinterluknews
    • Home
    • Business
      • Corporate News
      • Industry Insights
      • Startups & Entrepreneurship
      • Technology & Innovation
    • Economy
      • Economic Policy
      • Financial Analysis
      • Inflation & Interest Rates
      • Trade & Markets
    • Global
      • Conflicts & Security
      • Diplomacy
      • Global Trends
      • International Affairs
    • Lifestyle
      • Fashion
      • Food & Dining
      • Personal Development
      • Travel
    • Opinion
      • Columns
      • Editorials
      • Expert Opinions
      • Reader Voices
    • More
      • Politics
        • Elections
        • Government & Policy
        • International Relations
        • Political Analysis
      • Sports
        • Cricket
        • Football / Soccer
        • International Sports
        • Local Sports
      • Technology
        • Artificial Intelligence
        • Cybersecurity
        • Gadgets & Reviews
        • Tech News
      • South Africa News
    Facebook X (Twitter) Instagram
    interluknewsinterluknews
    Cybersecurity

    WinRAR Flaw Exploited by Russia-Aligned Groups to Deploy Stealers in Ukraine

    adminBy adminJune 9, 2026No Comments3 Mins Read
    Share Facebook Twitter Pinterest Copy Link Telegram LinkedIn Tumblr Email
    WinRAR Flaw Exploited by Russia-Aligned Groups to Deploy Stealers in Ukraine
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananJun 09, 2026Vulnerability / Cyber Espionage

    WinRAR Flaw Exploited by Russia-Aligned Groups to Deploy Stealers in Ukraine

    Two Russia-aligned cyber attack campaigns have continued to exploit a security flaw in WinRAR to target Ukrainian organisations, almost a year after patches for the vulnerability were released.

    The activity has been attributed by Trend Micro to Earth Dahu (aka Gamaredon) and SHADOW-EARTH-066 (aka UAC-0226). It involves the exploitation of CVE-2025-8088, a path traversal flaw that allows an attacker to write files outside the extraction directory via NTFS Alternate Data Streams (ADS). It was patched by WinRAR in July 2025.

    The findings show “how unmanaged software keeps an exploited entry point open long after the fix ships,” Trend Micro researchers Hiroyuki Kakara and Feike Hacquebord said in an analysis published Monday.

    The WinRAR exploit chain exploited by SHADOW-EARTH-066 is a departure from Excel macro droppers previously used by the threat actor to deliver an information stealer called GIFTEDCROOK. The latest iteration makes use of crafted RAR archives featuring a decoy PDF document and three hidden ADS payloads that are outside the extraction directory to initiate the infection.

    Cybersecurity

    This includes a Windows Shortcut (LNK) file that’s placed in the Startup folder so that it’s automatically executed every time a user logs in. This, in turn, spawns a PowerShell loader via “cmd.exe,” which then uses in-memory DLL loading to ultimately launch an updated version of GIFTEDCROOK (“result.dll”).

    The malware targets passwords and cookies from Chromium-based browsers (Google Chrome, Microsoft Edge, and Opera) and Mozilla Firefox, in addition to harvesting documents matching certain extensions from the victim’s machine. Once the data is exfiltrated to an external server, all malicious artifacts are deleted to cover up the forensic trail.

    A notable change is the shift from Telegram as an exfiltration channel to dedicated command-and-control (C2) servers, a key modification that likely aligns with Russia’s blocking of the messaging platform in the country earlier this February.

    The second Russia-affiliated hacking group to weaponize CVE-2025-8088 is Earth Dahu, which has incorporated the flaw into its arsenal since at least September 2025. The adversary is known for its “industrial-scale effort” to maintain long-term access to compromised organizations.

    “Earth Dahu used the vulnerability with an HTA-to-VBScript infection chain that delivered espionage modules,” Trend Micro noted. “Based on RAR internal file timestamps and file naming conventions, the chain remained active through at least April 10, 2026.”

    Cybersecurity

    These attacks, as recently also documented by Sekoia last week, lead to the deployment of GammaPhish, an HTML Application (HTA), which is then used to retrieve a VBScript downloader named GammaLoad. The intermediate downloader subsequently delivers additional modules like GammaSteel.

    GammaLoad is “a collection of VBScripts designed to ensure continuous access and deploy payloads over time by leveraging Dead Drop Resolvers (DDR),” Sekoia said, adding it’s used to deploy a dropper that’s designed to launch a VBScript loader responsible for executing GammaSteel, a comprehensive information stealer that can monitor changes to files in real-time.

    “WinRAR is deeply embedded in daily operations across Ukrainian organizations, making it an attractive target for exploitation,” Trend Micro said. “The convergence of both established state-backed groups and independently tracked clusters on a single vulnerability reflects the scale of the cyber threats that Ukraine faces.”

    deploy Exploited flaw groups RussiaAligned Stealers Ukraine WinRAR
    Follow on Google News Follow on Flipboard
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
    Previous ArticleWhy you need to stop using passwords and switch to this secure alternative now
    Next Article Nintendo Direct June 2026: All the news and trailers
    admin
    • Website

    Related Posts

    The Hidden Security Risk in Modern Networks: The Work Between Tools

    June 9, 2026

    LiteLLM Flaw CVE-2026-42271 Exploited in the Wild, Chains to Unauthenticated RCE

    June 9, 2026

    The Hardest Fork

    June 9, 2026
    Leave A Reply Cancel Reply

    Demo
    Latest Posts

    Apple’s App Store rolls out personalized recommendations

    Trump says in ‘final throes’ of peace deal but at least 8 killed in Lebanon | Benjamin Netanyahu News

    Golden Analytics lands $14M seed extension and opens AI platform to public beta – GeekWire

    Sandstone raises $30M to bring AI to in-house legal teams

    Latest Posts

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    Advertisement
    Demo

    We are a digital news platform delivering timely, accurate, and insightful coverage of politics, global affairs, business, economy, sports, and more. Our mission is to keep readers informed with reliable news, clear analysis, and stories that truly matter.
    We're social. Connect with us:

    Facebook X (Twitter) Instagram Pinterest YouTube

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.

    Powered by
    ...
    ►
    Necessary cookies enable essential site features like secure log-ins and consent preference adjustments. They do not store personal data.
    None
    ►
    Functional cookies support features like content sharing on social media, collecting feedback, and enabling third-party tools.
    None
    ►
    Analytical cookies track visitor interactions, providing insights on metrics like visitor count, bounce rate, and traffic sources.
    None
    ►
    Advertisement cookies deliver personalized ads based on your previous visits and analyze the effectiveness of ad campaigns.
    None
    ►
    Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
    None
    Powered by