Analysis of Gamaredon campaign targeting Ukraine weaponizing CVE-2025-8088
Essential information
- Published
- 19/06/2026 06:31
- Modified
- —
- Source / Author
- AlienVault
- Confidence
- 100/100
- Report type(s)
- threat-report
- Labels / Tags
- conscription-themed cve-2025-8088 gamaredon military-lures path-traversal persistence powershell ukraine winrar
- Related entities
- 1 vulnerabilities (cve), 10 indicators, 1 intrusion sets (apt), 10 techniques (mitre)
Description
A campaign exploiting the WinRAR path-traversal vulnerability CVE-2025-8088 has been actively targeting Ukraine since February 2026, with ongoing activity through June 2026. The operation uses Ukrainian military and conscription-themed documents as lures, distributed as RAR archives. The malicious archives contain NTFS alternate data streams with path-traversal sequences that automatically place LNK files into the Windows Startup folder upon extraction. These shortcuts execute hidden PowerShell stagers incorporating anti-analysis techniques including debugger checks, disk-space verification, and sleep delays to evade sandbox detection. The persistent nature of the attacks demonstrates continuous targeting of Ukrainian entities over a four-month period using social engineering focused on military documentation themes.