Still using WinRAR? You should probably look out for these potentially dangerous security flaws

  • WinRAR flaw CVE-2025-8088 exploited by state-sponsored and criminal groups
  • Attackers use ADS feature to deploy malware via malicious archives
  • Users urged to update to WinRAR 7.13 or newer for protection

Iconic Windows archiving program WinRAR contains a high-severity vulnerability that allows threat actors to execute arbitrary code on compromised endpoints – and security researchers are now saying the bug is being exploited by numerous hacking collectives, both state-sponsored and otherwise.

The bug in question is described as a path traversal flaw, affecting versions 7.12 and older. It is tracked as CVE-2025-8088, and was given a severity score of 8.4/10 (high).

In order to secure your premises and prevent hacker incursions, security pros advise updating the program to version 7.13, or newer.

Abused as a zero-day

Now, BleepingComputer is saying that multiple security outfits were warning about numerous hacking collectives using this flaw in their attacks.

Among them is RomCom, a Russia-aligned group, who used it to deploy NESTPACKER against Ukrainian military units. Other notable mentions include APT44 and Turla (also used against the Ukrainian military), Carpathian, and multiple Chinese state-sponsored actors who were allegedly using it to drop the POISONIVY malware.

Google’s Threat Intelligence Group (GTIG), the cybersecurity arm that mostly tracks state-sponsored attackers, said the earliest signs of abuse were seen in mid-July 2025. Since then, hackers were using the Alternate Data Streams (ADS) feature in WinRAR to write malware to arbitrary locations on target devices.

“While the user typically views a decoy document, such as a PDF, within the archive, there are also malicious ADS entries, some containing a hidden payload while others are dummy data,” Google said.

When the victim opens the archive, the program extracts the ADS payload using directory traversal, it was explained.

Besides nation-states, financially motivated groups were also leveraging this bug, using it to drop infostealers such as XWorm, or AsyncRAT.

WinRAR does not allow automatic updates, but you don’t need to uninstall the program before running the new version. It will just be installed over the existing one.

Via BleepingComputer

Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds. Make sure to click the Follow button!

And of course you can also follow TechRadar on TikTok for news, reviews, unboxings in video form, and get regular updates from us on WhatsApp too.

Read more @ TechRadar

Latest posts

Alienware’s fast 27-inch QD-OLED gaming monitor is 23 percent off

One of the best upgrades you can make to your gaming PC setup is an OLED monitor. Assuming that games already run great on...

This backup camera cleaner hides behind your license plate

The Lens Lizard is installed using your car’s existing license plate screw holes. | Image: Lens Lizard A Vermont-based startup has announced a new upgrade...

WordPress’ new AI assistant will let users edit their sites with prompts

Starting on Tuesday, WordPress users can edit their websites using the new AI assistant built into the platform's site editor and media library, TechCrunch...

Apple is reportedly planning to launch AI-powered glasses, a pendant, and AirPods

The second-gen Ray-Ban Meta smart glasses. | Photo by Amelia Holowaty Krales / The Verge Apple is pushing ahead with plans to launch its first...

Now Pixel 9 phones can transfer files with AirDrop, too

Google is expanding the AirDrop compatibility it first offered in the Pixel 10 (above). | Photo: Allison Johnson / The Verge When Google announced it...

Kingdom Come: Deliverance 2 and The Witcher 3 are coming to Game Pass

Xbox has revealed the second batch of Game Pass additions for February. There are quite a few heavyweights in the mix this time, including...

The first full trailer for The Mandalorian and Grogu is here

Fans of The Mandalorian and his tiny green apprentice Grogu are getting their best look yet at the duo's upcoming theatrical adventure, set for...

Netflix is streaming its first MMA fight on May 16

Netflix is streaming its very first live MMA fight on May 16. The combatants are one-time phenom Ronda Rousey and one-time actor Gina Carano....

WordPress adds an AI assistant

Web designers of the world: The Automattic-owned WordPress.com is further embracing AI on its platform. On Tuesday, it expanded its one-off AI site builder...

Netflix is adapting the board game Ticket to Ride

Netflix has been in the game adaptation business for a while now, but until recently most of its attention had been on adapting video...