[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-150620-en":3,"doc-seo-150620-105":30,"detail-sidebar-cat-0-en-105":92},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":27,"seo_description":14,"update_tm":28,"read_time":29},150620,687197207919,"Theodora","https://ap-avatar.wpscdn.com/avatar/a000253d6f5f7c60be?x-image-process=image/resize,m_fixed,w_180,h_180&k=1779446848396160552",6,"Technology","Update WinRAR tools now - RomCom and others exploiting zero-day vulnerability - ESET Research","ESET Research reports a previously unknown zero-day vulnerability in WinRAR that is actively exploited in the wild under the guise of job-application documents. The attack uses path traversal via alternate data streams to hide malicious files inside crafted RAR archives, which are deployed silently when users extract them. The exploitation chain supports persistence by placing components in the Windows startup and staging backdoors associated with the RomCom group, targeting organizations in Europe and Canada.","WELIVESECURITY.COM PUBLICATION  \nUpdate WinRAR tools now: RomCom and others exploiting zero-day vulnerability  \nUpdate WinRAR tools now: RomCom and others exploiting zeroday vulnerability  \nESET Research discovered a zero-day vulnerability in WinRAR being exploited in the wild in the guise of job application documents; the weaponized archives exploited a path traversal flaw to compromise their targets  \nESET researchers have discovered a previously unknown vulnerability in WinRAR, being exploited in the wild by Russia-aligned group RomCom. This is at least the third time that RomCom has been caught exploiting a significant zero-day vulnerability in the wild. Previous examples include the abuse of CVE-2023-36884 via Microsoft Word in June 2023, and the combined vulnerabilities assigned CVE-2024-9680 chained with another previously unknown vulnerability in Windows, CVE-2024-49039, targeting vulnerable versions of Firefox, Thunderbird, and the Tor Browser, leading to arbitrary code execution in the context of the logged-in user in October 2024.  \nKey points of this blogpost:  \n• If you use WinRAR or other affected components such as the Windows versions of its command line utilities, UnRAR.dll, or the portable UnRAR source code, upgrade immediately to the latest version.  \n• On July 18th, 2025, ESET researchers discovered a previously unknown zero-day vulnerability in WinRAR being exploited in the wild.  \n• Analysis of the exploit led to the discovery of the vulnerability, now assigned CVE-2025-8088: a path traversal vulnerability, made possible with the use of alternate data streams. After immediate notification, WinRAR released a patched version on July 30th, 2025.  \n• The vulnerability allows hiding malicious files in an archive, which are silently deployed when extracting.  \n• Successful exploitation attempts delivered various backdoors used by the RomCom group, specifically a SnipBot variant, RustyClaw, and Mythic agent.  \n• This campaign targeted financial, manufacturing, defense, and logistics companies in Europe and Canada.  \nROMCOM PROFILE  \nRomCom (also known as Storm-0978, Tropical Scorpius, or UNC2596) is a Russia-aligned group that conducts both opportunistic campaigns against selected business verticals and targeted espionage operations. The group’s focus has shifted to include espionage operations collecting intelligence, in parallel with its more conventional cybercrime operations. The backdoor commonly used by the group is capable of executing commands and downloading additional modules to the victim’s machine.  \nTHE DISCOVERY OF CVE-2025-8088  \nOn July 18th, 2025, we observed a malicious DLL named msedge .dll in a RAR archive containing unusual paths that caught our attention. Upon further analysis, we found that the attackers were exploiting a previously unknown vulnerability affecting WinRAR, including the then-current version, 7.12. On July 24th, 2025, we contacted the developer of WinRAR, and on the same day, the vulnerability was fixed and WinRAR 7.13 beta 1 published. WinRAR 7.13 was published on July 30th, 2025. Users of WinRAR are advised to install the latest version as soon as possible to mitigate the risk. Note that software solutions relying on publicly available Windows versions of UnRAR.dll or its corresponding source code are affected as well, especially those that have not updated their dependencies.  \nThe vulnerability, tracked as CVE-2025-8088, uses alternate data streams (ADSes) for path traversal. Note that a similar path traversal vulnerability (CVE-2025-6218) affecting WinRAR was disclosed on June 19th, 2025, approximately a month earlier.  \nThe attackers specially crafted the archive to apparently contain only one benign file (see Figure 1), while it contains many malicious ADSes (there’s no indication of them from the user’s point of view) .  \nFigure 1. Eli_Rosenfeld_CV2 - Copy (10) .rar opened in WinRAR  \nOnce a victim opens this seemingly benign file, WinRAR unpacks it along with all it","cbCaip3MwXbUsmL4","https://ap.wps.com/l/cbCaip3MwXbUsmL4","pdf",906115,1,12,"English","en",105,"# Key points and timeline\n## Immediate upgrade guidance\n## Discovery, CVE assignment, and patch release\n# RomCom profile\n# The discovery of CVE-2025-8088\n## Observed malicious archive behavior\n## Path traversal using alternate data streams\n## Persistence mechanisms\n# Compromise chain and targeting\n## Spearphishing timing and geographies","[{\"question\":\"What vulnerability affects WinRAR, and how is it exploited?\",\"answer\":\"ESET identifies CVE-2025-8088, a path traversal vulnerability enabled by alternate data streams. Attackers hide malicious payloads in RAR archives so they are deployed silently when the archive is extracted.\"},{\"question\":\"What should users do to reduce risk?\",\"answer\":\"Upgrade WinRAR (and any affected components such as UnRAR.dll or dependent solutions) immediately to the latest available version. ESET notes a patched release was published after the vulnerability was disclosed.\"},{\"question\":\"Who is behind the attacks and what targets were affected?\",\"answer\":\"ESET links exploitation to the RomCom group (also known under several aliases). The spearphishing campaigns targeted financial, manufacturing, defense, and logistics companies in Europe and Canada, though ESET reports no compromised targets in observed telemetry.\"}]","Update WinRAR tools now - RomCom and others exploiting zero-day vulnerability - ESET Research | PDF",1787823989,30,{"code":4,"msg":31,"data":32},"ok",{"site_id":24,"language":23,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":87,"head_meta":89,"extra_data":91,"updated_unix":28},"update-winrar-tools-now-romcom-and-others-exploiting-zero-day-vulnerability-eset-research","",{"@graph":36,"@context":86},[37,54,69],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/technology/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/update-winrar-tools-now-romcom-and-others-exploiting-zero-day-vulnerability-eset-research/150620/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":23,"description":14,"dateModified":62,"datePublished":63,"encodingFormat":61,"isAccessibleForFree":64,"interactionStatistic":65},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-09-04","2026-08-27",true,{"@type":66,"interactionType":67,"userInteractionCount":20},"InteractionCounter",{"@type":68},"ViewAction",{"@type":70,"mainEntity":71},"FAQPage",[72,78,82],{"name":73,"@type":74,"acceptedAnswer":75},"What vulnerability affects WinRAR, and how is it exploited?","Question",{"text":76,"@type":77},"ESET identifies CVE-2025-8088, a path traversal vulnerability enabled by alternate data streams. Attackers hide malicious payloads in RAR archives so they are deployed silently when the archive is extracted.","Answer",{"name":79,"@type":74,"acceptedAnswer":80},"What should users do to reduce risk?",{"text":81,"@type":77},"Upgrade WinRAR (and any affected components such as UnRAR.dll or dependent solutions) immediately to the latest available version. ESET notes a patched release was published after the vulnerability was disclosed.",{"name":83,"@type":74,"acceptedAnswer":84},"Who is behind the attacks and what targets were affected?",{"text":85,"@type":77},"ESET links exploitation to the RomCom group (also known under several aliases). The spearphishing campaigns targeted financial, manufacturing, defense, and logistics companies in Europe and Canada, though ESET reports no compromised targets in observed telemetry.","https://schema.org",{"og:url":52,"og:type":88,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":90,"canonical":52},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":93},[94,98,102,106,111,114,119,123,128,131,135],{"id":20,"doc_module":4,"doc_module_name":46,"category_name":95,"show_sort_weight":96,"slug":97},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":99,"show_sort_weight":100,"slug":101},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":103,"show_sort_weight":104,"slug":105},"Exam",70,"exam",{"id":107,"doc_module":4,"doc_module_name":46,"category_name":108,"show_sort_weight":109,"slug":110},5,"Comic",60,"comic",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":112,"slug":113},50,"technology",{"id":115,"doc_module":4,"doc_module_name":46,"category_name":116,"show_sort_weight":117,"slug":118},7,"Healthcare",40,"healthcare",{"id":120,"doc_module":4,"doc_module_name":46,"category_name":121,"show_sort_weight":29,"slug":122},8,"Research & Report","research-report",{"id":124,"doc_module":4,"doc_module_name":46,"category_name":125,"show_sort_weight":126,"slug":127},9,"Religion & Spirituality",20,"religion-spirituality",{"id":126,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":126,"slug":130},"World Cup","world-cup",{"id":132,"doc_module":4,"doc_module_name":46,"category_name":133,"show_sort_weight":132,"slug":134},10,"Lifestyle","lifestyle",{"id":136,"doc_module":4,"doc_module_name":46,"category_name":137,"show_sort_weight":107,"slug":138},19,"General","general"]