Utopia Tech
SecurityAI-assisted1 min read

WinRAR Flaw Exploited by Russia-Aligned Groups to Deploy Stealers in Ukraine

Two Russia-aligned threat groups, Earth Dahu (Gamaredon) and SHADOW-EARTH-066 (UAC-0226), continue to exploit a patched WinRAR vulnerability (CVE-2025-8088) to target Ukrainian organizations nearly a year after fixes were released. The campaigns leverage a path traversal flaw to deploy information-stealing malware against Ukrainian entities, demonstrating persistent targeting despite available sec

UT

Utopia Tech

June 9, 2026 · 1 min read

Share

Two Russia-aligned cyber attack campaigns have continued to exploit a security flaw in WinRAR to target Ukrainian organisations, almost a year after patches for the vulnerability were released. The activity has been attributed by Trend Micro to Earth Dahu (aka Gamaredon) and SHADOW-EARTH-066 (aka UAC-0226). It involves the exploitation of CVE-2025-8088, a path traversal flaw that allows an

Originally published at thehackernews.com

Share
▸ Want a deeper look?

Talk to an architect about applying this to your stack.

60-minute technical evaluation, no obligation. We'll map the ideas in this article to your environment.

Skip to main content