Two Russian FSB-linked APT groups, Gamaredon (Earth Dahu) and SHADOW-EARTH-066 (UAC-0226), are actively exploiting CVE-2025-8088, a path traversal vulnerability in WinRAR rated 8.4 CVSS, to target Ukrainian government and military organizations. The flaw, which abuses NTFS Alternate Data Streams to hide malicious payloads in archive files, was patched in WinRAR 7.13 on July 30, 2025, but slow update adoption keeps organizations exposed. Gamaredon deploys a multi-stage chain ending in GammaSteel for document exfiltration, while SHADOW-EARTH-066 uses GIFTEDCROOK to steal browser credentials and session cookies from Chrome, Edge, Opera, and Firefox. A third group, RomCom, was the first to weaponize the flaw before the patch shipped. Gamaredon has also shifted C2 infrastructure away from Telegram following Russia's throttling of the platform in February 2026. Organizations still on WinRAR 7.12 or earlier should update immediately and consider blocking NTFS Alternate Data Streams at the email gateway.