216.73.216.36

Update WinRAR tools now: RomCom and others exploiting zero-day vulnerability

· Published 11/08/2025 14:56 · Modified 11/08/2025 15:41

Export JSON

Essential information

Published
11/08/2025 14:56
Modified
11/08/2025 15:41
Tags
2025-08-11 CVE-2025-8088 backdoor exploit mythic russia-aligned rustyclaw snipbot spearphishing vulnerability winrar zero-day
Related entities
2 vulnerabilities (cve), 9 observables, 1 intrusion sets (apt), 3 malware, 4 others

Description

A in , , has been discovered being exploited in the wild by the group RomCom. The allows attackers to hide malicious files in archives, which are silently deployed when extracted. The was used in campaigns targeting financial, manufacturing, defense, and logistics companies in Europe and Canada. Three execution chains were identified, delivering various backdoors including a variant, , and agent. This marks the third time RomCom has exploited a significant , highlighting their focus on acquiring and using exploits for targeted attacks. Users are advised to update immediately to mitigate the risk.

External references