WinRAR Exploit: Russia-Aligned Groups Target Ukraine with Stealers (2026)

In the ongoing conflict between Ukraine and Russia, the digital battleground has become a crucial arena, with cyberattacks serving as a powerful weapon. A recent development has brought to light a sophisticated exploit chain targeting Ukrainian organizations through a seemingly innocuous software tool: WinRAR. This incident not only highlights the evolving nature of cyber threats but also underscores the critical need for robust cybersecurity measures in the face of state-sponsored attacks.

The WinRAR Flaw: A Persistent Vulnerability

The story begins with a security flaw in WinRAR, a popular file archiver, which was patched in July 2025. However, the damage had already been done. Two Russia-aligned groups, Earth Dahu and SHADOW-EARTH-066, had already exploited this vulnerability to target Ukrainian organizations. The flaw, CVE-2025-8088, allowed attackers to write files outside the extraction directory via NTFS Alternate Data Streams (ADS), providing them with a backdoor into the systems.

What makes this exploit chain particularly insidious is its persistence. Trend Micro researchers noted that the chain remained active through at least April 10, 2026, demonstrating how unmanaged software can leave an open entry point long after a fix is released. This is a stark reminder of the importance of prompt patching and the need for organizations to stay vigilant against zero-day exploits.

The Evolution of the Attack Chain

SHADOW-EARTH-066's attack chain marked a departure from Excel macro droppers previously used to deliver the GIFTEDCROOK information stealer. Instead, they crafted RAR archives featuring a decoy PDF document and three hidden ADS payloads. One of these payloads was a Windows Shortcut (LNK) file placed in the Startup folder, ensuring automatic execution upon user login. This led to the execution of a PowerShell loader via 'cmd.exe', which in turn loaded an updated version of GIFTEDCROOK, now known as 'result.dll'.

The malware targeted passwords and cookies from Chromium-based browsers and Mozilla Firefox, as well as harvesting documents with specific extensions. Once the data was exfiltrated to an external server, all malicious artifacts were deleted to cover up the forensic trail. A notable change was the shift from Telegram as an exfiltration channel to dedicated command-and-control (C2) servers, a move likely aligned with Russia's blocking of the messaging platform in February.

Earth Dahu's Industrial-Scale Effort

Earth Dahu, the second Russia-affiliated group to weaponize CVE-2025-8088, has been active since at least September 2025. Known for its industrial-scale effort to maintain long-term access to compromised organizations, Earth Dahu used the vulnerability with an HTA-to-VBScript infection chain that delivered espionage modules. The chain remained active through at least April 10, 2026, based on RAR internal file timestamps and file naming conventions.

These attacks lead to the deployment of GammaPhish, an HTML Application (HTA), which retrieves a VBScript downloader named GammaLoad. GammaLoad, in turn, delivers additional modules like GammaSteel, a comprehensive information stealer capable of monitoring changes to files in real-time. This sophisticated chain of events underscores the complexity and sophistication of modern cyberattacks.

Implications and Future Developments

The convergence of both established state-backed groups and independently tracked clusters on a single vulnerability reflects the scale of the cyber threats that Ukraine faces. WinRAR's deep embedding in daily operations across Ukrainian organizations makes it an attractive target for exploitation. This incident serves as a stark reminder of the need for robust cybersecurity measures, including prompt patching, vigilant monitoring, and the adoption of zero-trust architectures.

Looking ahead, the evolution of cyber threats is likely to continue, with attackers constantly adapting their methods to exploit new vulnerabilities. Organizations must stay ahead of the curve by investing in cybersecurity, fostering a culture of awareness, and collaborating with industry peers and government agencies to combat these threats effectively.

In conclusion, the WinRAR exploit chain targeting Ukrainian organizations is a stark reminder of the ongoing cyber conflict between Ukraine and Russia. It underscores the critical need for robust cybersecurity measures and highlights the importance of staying vigilant against zero-day exploits. As we move forward, organizations must continue to invest in cybersecurity, foster a culture of awareness, and collaborate to combat these threats effectively.

WinRAR Exploit: Russia-Aligned Groups Target Ukraine with Stealers (2026)

References

Top Articles
Latest Posts
Recommended Articles
Article information

Author: Lilliana Bartoletti

Last Updated:

Views: 6472

Rating: 4.2 / 5 (53 voted)

Reviews: 84% of readers found this page helpful

Author information

Name: Lilliana Bartoletti

Birthday: 1999-11-18

Address: 58866 Tricia Spurs, North Melvinberg, HI 91346-3774

Phone: +50616620367928

Job: Real-Estate Liaison

Hobby: Graffiti, Astronomy, Handball, Magic, Origami, Fashion, Foreign language learning

Introduction: My name is Lilliana Bartoletti, I am a adventurous, pleasant, shiny, beautiful, handsome, zealous, tasty person who loves writing and wants to share my knowledge and understanding with you.