<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/diverse-threat-actors-exploiting-critical-winrar-vulnerability-cve-2025-8088-uaotwknob" -->

---
title: Diverse Threat Actors Exploiting Critical WinRAR...
description: Google Threat Intelligence Group reports widespread exploitation of CVE-2025-8088, a critical path traversal vulnerability in WinRAR patched in July 2025....
canonical: https://daily.dev/posts/diverse-threat-actors-exploiting-critical-winrar-vulnerability-cve-2025-8088-uaotwknob
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Diverse Threat Actors Exploiting Critical WinRAR Vulnerability CVE-2025-8088 | daily.dev
og:description: Google Threat Intelligence Group reports widespread exploitation of CVE-2025-8088, a critical path traversal vulnerability in WinRAR patched in July 2025....
og:url: https://daily.dev/posts/diverse-threat-actors-exploiting-critical-winrar-vulnerability-cve-2025-8088-uaotwknob
og:image: https://api.daily.dev/og/posts/UaotWknOB.png
og:image:alt: Diverse Threat Actors Exploiting Critical WinRAR Vulnerability CVE-2025-8088
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Diverse Threat Actors Exploiting Critical WinRAR Vulnerability CVE-2025-8088

**[Google Cloud](https://daily.dev/sources/gcp)** · 7 min read · 0 upvotes · 0 comments

## Summary

Google Threat Intelligence Group reports widespread exploitation of CVE-2025-8088, a critical path traversal vulnerability in WinRAR patched in July 2025. State-sponsored actors from Russia and China, along with financially motivated groups, are actively exploiting this n-day vulnerability to drop malicious payloads into Windows Startup folders for persistence. Russian groups like UNC4895, APT44, and Turla target Ukrainian military and government entities, while Chinese actors deploy POISONIVY malware. Financially motivated actors use the exploit to deliver commodity RATs and stealers across various sectors. The vulnerability's exploitation involves crafting malicious RAR archives using Alternate Data Streams to write files to arbitrary system locations. Organizations should immediately update WinRAR to version 7.13 or later and implement detection for post-exploitation tactics.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://cloud.google.com/blog/topics/threat-intelligence/exploiting-critical-winrar-vulnerability/>

## Similar posts on daily.dev

- [Warning: WinRAR Vulnerability CVE-2025-6218 Under Active Attack by Multiple Threat Groups](https://daily.dev/posts/warning-winrar-vulnerability-cve-2025-6218-under-active-attack-by-multiple-threat-groups-hmvdlq63x) · The Hacker News · 1 upvotes · 0 comments
- [Two Russian APT groups are exploiting a WinRAR flaw patched nearly a year ago to hit Ukraine](https://daily.dev/posts/two-russian-apt-groups-are-exploiting-a-winrar-flaw-patched-nearly-a-year-ago-to-hit-ukraine-n4zbqznuu) · The Next Web · 0 upvotes · 0 comments
- [The “Unzip” of Death: Why Using Your Old WinRAR Is a Dangerous Trap](https://daily.dev/posts/the-unzip-of-death-why-using-your-old-winrar-is-a-dangerous-trap-bwbzk88fe) · InfoSec Write-ups · 0 upvotes · 0 comments

---

Tags: [#cyber](https://daily.dev/tags/cyber), [#malware](https://daily.dev/tags/malware), [#vulnerability](https://daily.dev/tags/vulnerability)

[View this post on daily.dev](https://daily.dev/posts/diverse-threat-actors-exploiting-critical-winrar-vulnerability-cve-2025-8088-uaotwknob)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Diverse Threat Actors Exploiting Critical WinRAR Vulnerability CVE-2025-8088","url":"https://daily.dev/posts/diverse-threat-actors-exploiting-critical-winrar-vulnerability-cve-2025-8088-uaotwknob","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/diverse-threat-actors-exploiting-critical-winrar-vulnerability-cve-2025-8088-uaotwknob"},"datePublished":"2026-01-27T15:09:08.351Z","dateModified":"2026-02-27T12:25:58.907Z","description":"Google Threat Intelligence Group reports widespread exploitation of CVE-2025-8088, a critical path traversal vulnerability in WinRAR patched in July 2025....","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/efb6ebdd31507ed6cdc6e0fe53ac3537?_a=AQAEulh","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/efb6ebdd31507ed6cdc6e0fe53ac3537?_a=AQAEulh","isAccessibleForFree":true,"articleSection":"Google Cloud","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Google Cloud","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/gcp","url":"https://daily.dev/sources/gcp"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/diverse-threat-actors-exploiting-critical-winrar-vulnerability-cve-2025-8088-uaotwknob","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"cyber,malware,vulnerability","timeRequired":"PT7M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Google Cloud","item":"https://daily.dev/sources/gcp"},{"@type":"ListItem","position":3,"name":"Diverse Threat Actors Exploiting Critical WinRAR Vulnerability CVE-2025-8088"}]}
```

