Russian hackers exploited a WinRAR zero-day vulnerability to attack Europe and Canada.
Two Russian hacking groups exploited a WinRAR zero-day vulnerability to spread malware via phishing emails, targeting carefully selected individuals.
Quick summary:
The WinRAR vulnerability CVE-2025-8088 was exploited for weeks, affecting millions of users.
Two Russian hacking groups, RomCom and Paper Werewolf, both exploited the vulnerability to spread malware.
Attack techniques include COM hijacking, installing SnipBot, RustyClaw, and Melting Claw.
WinRAR does not update automatically; you need to upgrade to version 7.13 to avoid risks.
The CVE-2025-8088 vulnerability and how to exploit it.
The popular file compression software WinRAR has just patched the critical vulnerability CVE-2025-8088 after it had been exploited for weeks. The vulnerability is a path traversal that exploits Windows' alternate data streams feature, allowing malicious files to be extracted into system folders such as %TEMP% or %LOCALAPPDATA – which are capable of executing code.
ESET detected signs of the attack on July 18th when it discovered an unusual file in a suspicious path. Just six days after being notified, WinRAR released a patch on July 30th (version 7.13).

RomCom and Paper Werewolf are working together on this project.
ESET identified RomCom – a financially motivated cybercriminal group operating in Russia for a long time – as being behind part of the attack. This is the third time the group has used a zero-day vulnerability in targeted campaigns.
Notably, the Russian cybersecurity company Bi.ZONE reported that another group, Paper Werewolf (also known as GOFFEE), is also exploiting CVE-2025-8088 in parallel. Paper Werewolf is also taking advantage of CVE-2025-6218, another WinRAR vulnerability patched five weeks earlier, through emails impersonating employees of the All-Russian Research Institute to install malware on victims' systems.
It is currently unclear whether these two groups are linked or purchased information from the same source on the black market.
A sophisticated series of attacks
According to ESET, RomCom deployed three main attack sequences:
COM hijacking: Malicious DLL files within compressed files are activated by applications such as Microsoft Edge, decrypting the shellcode to check machine information and installing a Mythic Agent attack tool if appropriate.
Executable Payload: Runs the Windows executable file to install SnipBot, spyware that blocks analytics in virtual environments.
Multilayer malware: Uses other malicious code such as RustyClaw and Melting Claw to maintain access and control.
Risks from delayed WinRAR updates
WinRAR has been targeted by hackers numerous times due to its large user base (around 500 million) and the lack of automatic updates. Users have to manually download and install patches, leaving many systems with long-term vulnerabilities.
ESET recommends avoiding all versions of WinRAR prior to 7.13 and updating immediately to fix all known vulnerabilities.


