WinRAR Zero-Day Vulnerability CVE-2025-8088 Exploited by RomCom to Deliver Backdoor Malware
On August 11, 2025, researchers at ESET disclosed a critical zero-day in WinRAR, the file archiver running on a huge number of Windows machines. The flaw, CVE-2025-8088, was already being exploited in the wild by the Russia-aligned cyber-espionage group RomCom (also tracked as Storm-0978, Tropical Scorpius, or UNC2596) in targeted spear-phishing campaigns.
I track campaigns like this for a living, and RomCom is a name that keeps coming up. They have a pattern: pick a tool everyone uses, find a way to weaponize it, and wrap it in social engineering that fits the target.
The Vulnerability Itself
CVE-2025-8088 is a high-severity (CVSS score 8.4) path traversal flaw in the Windows builds of WinRAR and its components, including UnRAR.dll and the portable UnRAR source code.
The trick relies on alternate data streams (ADSes) to mess with where files land during extraction. By crafting those paths, an attacker can drop arbitrary files, executables or LNK shortcuts, into sensitive locations like the Windows Startup directories. From there, the payload runs automatically at the next login or reboot.
Affected Versions and the Fix
- Affected: every Windows release of WinRAR up to and including version 7.12
- Fixed: WinRAR version 7.13, released on July 30, 2025
- Critical note: WinRAR has no auto-update, so users have to manually download and install the patched build
That last point is the one that bites organizations. A patch only helps if someone actually applies it, and WinRAR won't nag anyone to do so.
The Campaign and Its Timeline
Between July 18 and 21, 2025, RomCom sent spear-phishing emails dressed up as job applications, each carrying a malicious RAR attachment that abused this flaw. The archives hid ADS data with crafted paths that pushed WinRAR to extract backdoor payloads into sensitive folders, setting up persistent compromise.
The Backdoors They Dropped
The planted backdoors included variants such as:
- Mythic Agent
- SnipBot
- RustyClaw
- MeltingClaw
These handled remote command execution, credential theft, and further payload delivery. The targeting hit finance, defense, logistics, and manufacturing across Europe and Canada.
It Didn't Stop With RomCom
Soon after RomCom's activity, a second actor, Paper Werewolf (aka GOFFEE), was seen exploiting CVE-2025-8088, mostly against Russian organizations. Word is the exploit changed hands for around $80,000 on cybercriminal forums. When a working zero-day starts getting resold like that, expect the volume of attacks to climb fast.
Walking Through the Exploit
- A user gets a spear-phishing email with a booby-trapped RAR archive posing as a resume or job-related document.
- WinRAR extracts files normally, but it also processes hidden ADS entries with relative paths like
....that climb out of the chosen extraction folder. - Malicious executables and LNK files land in critical folders such as the Startup directory.
- The LNK files fire the RomCom backdoor at system startup or user login.
- The backdoors give the operators remote control, data theft, and a launchpad for more activity.
Recommendations and Mitigations
Do These Now
- Update WinRAR and every related component to version 7.13 or later.
- Block or quarantine RAR/ZIP attachments from unknown or untrusted senders at the email gateway.
- Detonate compressed files in a sandbox before they reach end users.
Then Harden Around It
- Restrict write permissions on Startup folders and other sensitive directories to trusted processes only.
- Use application allow-listing so unauthorized executables can't launch.
- Train users on the risk of unsolicited attachments, even ones that look like genuine job applications.
- Hunt for indicators of compromise (IOCs) tied to RomCom and the exploit's behavior.
IOCs Available
VirusTotal Collection with the relevant indicators of compromise.
The MINE2 Angle
This zero-day is a textbook case of trusted software becoming the attack vector. Conventional controls tend to struggle once an attacker is working through a tool you already allow, and that's exactly the gap deception was built for.
How MINE2 helps:
- Email deception that flags and analyzes suspicious attachments before they reach users
- File system monitoring through honeypots planted in startup directories
- Behavioral analysis that catches unusual file extraction patterns
- Lateral movement detection when backdoors try to spread across the network
Catching activity after the initial foothold is what counts against a patient group like RomCom. The same logic carries over to the phishing campaigns that weaponize Cisco Safe Links and to APT28's SOHO router and DNS hijacking: once they're in, you want a tripwire they can't see.
See how deception technology holds up against advanced threats.
Why This Matters
Bugs in widely trusted utilities like WinRAR are dangerous precisely because the software is everywhere and rarely questioned. Bending extraction paths to plant persistent malware through a phishing email is a potent technique, and a quiet one.
Given RomCom's track record of using zero-days for espionage, the sectors they hit, and how stealthy these backdoors are, fast patching and layered defense aren't optional.
Key Takeaways
- What: WinRAR zero-day CVE-2025-8088, exploited via ADS path traversal to plant malware.
- Who: Russia-aligned RomCom (and later Paper Werewolf), hitting finance, defense, logistics, and manufacturing.
- Impact: Persistent backdoors with remote code execution, data theft, and ongoing control.
- Fix: Update to WinRAR 7.13 immediately and enforce strict attachment and execution policies.
- Importance: The attack abuses trusted software, so vigilance and multi-layered defense matter.
Summary
Patch promptly, tighten your controls, and you can blunt this zero-day and the broader wave of supply-chain-style threats it represents. The bigger lesson is plain: even trusted, everyday software can turn into an attack vector. Keep your defenses layered with fast patching, user education, and detection that doesn't quit at the perimeter. For more on how a similarly trusted Windows component gets abused, see our look at the BitUnlocker flaws in Windows Recovery Environment.
Stay protected against evolving threats with MINE2's comprehensive cybersecurity intelligence and deception technology.
Riya
Principal Threat Researcher, Mine2 Labs
Riya tracks active threat campaigns and APT tradecraft at Mine2 Labs, translating real-world attacker behaviour into practical detection ideas.
Recent Articles
Fortinet SSL VPN and FortiManager Under Coordinated Brute-Force Campaign: August 2025 Threat Analysis
27 Seconds: What CrowdStrike's 2026 Threat Report Really Means for Your Detection Stack
One Token, Dozens of Victims: How the Anodot SaaS Integration Breach Rewrites the Third-Party Risk Playbook
Need Security Help?
Protect your organization with MINE2's cyber deception platform.

