Two Russia-aligned threat actor groups — SHADOW-EARTH-066 (UAC-0226) and Earth Dahu (Gamaredon) — are actively exploiting CVE-2025-8088, a path traversal vulnerability in WinRAR patched in July 2025, against Ukrainian government and military organizations. The flaw allows silent file writes outside the extraction directory via NTFS Alternate Data Streams, requiring no user interaction beyond opening the archive. SHADOW-EARTH-066 deploys an evolved GIFTEDCROOK information stealer (result.dll) that harvests browser credentials, session cookies, and 35 file types, using in-memory DLL loading via direct NT syscalls and RC4-encrypted C&C communication. Earth Dahu uses an HTA-based chain delivering espionage modules through Cloudflare Workers infrastructure. Both groups continue producing new exploit samples as late as April 2026. The persistence of exploitation is attributed to WinRAR's lack of auto-update and exclusion from enterprise patch management channels like WSUS, SCCM, and Intune. Detailed IOCs, MITRE ATT&CK mappings, and remediation guidance are provided.