WinRAR Vulnerability Exploited by State and Criminal Hackers

In a concerning cybersecurity scenario that has persisted for months, a serious security flaw in the popular compression software WinRAR has allowed various hacker groups to compromise computer systems worldwide. The vulnerability, identified as CVE-2025-8088, was discovered and patched in July 2025, but attacks continued until January 2026, highlighting how many users do not regularly update their software.

According to verified information, malicious actors linked to Russia and China, along with criminally motivated groups, have actively exploited this vulnerability to infiltrate systems and distribute various types of malware. Among the identified groups is RomCom (also known as CIGAR/UNC4895), which used the flaw to establish initial access and distribute harmful programs such as SnipBot/NESTPACKER, AsyncRAT, XWorm, Telegram bot-controlled backdoors, and Cuba ransomware. Particularly concerning was also a criminal group that targeted Brazilian users, distributing malicious Chrome extensions designed to insert harmful JavaScript code used in phishing attacks against Brazilian banking sites.

The impact of this vulnerability is significant as WinRAR is one of the most widely used file compression software in the world, installed on millions of computers. The persistence of attacks for over six months demonstrates that many users and companies have not applied available security patches, exposing themselves to considerable risks such as theft of sensitive data, ransomware extortion, and potentially industrial or government espionage. The attackers’ ability to use this vulnerability to distribute different types of malware highlights the versatility and danger of this flaw.

To protect themselves, companies and users should immediately verify the version of WinRAR installed on their systems and update to the latest available version, which has fixed the vulnerability. It is also advisable to run complete antivirus scans to identify any malware already present in the system, monitor suspicious activities, and, in the case of companies, implement multi-layered security solutions that can detect and block attempts to exploit known vulnerabilities.

  • Key points to remember:
  • A serious vulnerability in WinRAR (CVE-2025-8088) has been exploited by state and criminal actors to distribute malware, despite being fixed in July 2025
  • Attacks have involved various types of malware, including ransomware and banking phishing tools, with a potentially global impact
  • Immediate software updates and system scanning are essential steps to protect against this threat

Sources:
https://thehackernews.com/2026/01/google-warns-of-active-exploitation-of.html
https://cloud.google.com/blog/topics/threat-intelligence/exploiting-critical-winrar-vulnerability/

Source: The Hacker News