MarketAlert – Real-Time Market & Crypto News, Analysis & AlertsMarketAlert – Real-Time Market & Crypto News, Analysis & Alerts
Font ResizerAa
  • Crypto News
    • Altcoins
    • Bitcoin
    • Blockchain
    • DeFi
    • Ethereum
    • NFTs
    • Press Releases
    • Latest News
  • Blockchain Technology
    • Blockchain Developments
    • Blockchain Security
    • Layer 2 Solutions
    • Smart Contracts
  • Interviews
    • Crypto Investor Interviews
    • Developer Interviews
    • Founder Interviews
    • Industry Leader Insights
  • Regulations & Policies
    • Country-Specific Regulations
    • Crypto Taxation
    • Global Regulations
    • Government Policies
  • Learn
    • Crypto for Beginners
    • DeFi Guides
    • NFT Guides
    • Staking Guides
    • Trading Strategies
  • Research & Analysis
    • Blockchain Research
    • Coin Research
    • DeFi Research
    • Market Analysis
    • Regulation Reports
Reading: Russian Hackers Exploit WinRAR Zero-Day
Share
Font ResizerAa
MarketAlert – Real-Time Market & Crypto News, Analysis & AlertsMarketAlert – Real-Time Market & Crypto News, Analysis & Alerts
Search
  • Crypto News
    • Altcoins
    • Bitcoin
    • Blockchain
    • DeFi
    • Ethereum
    • NFTs
    • Press Releases
    • Latest News
  • Blockchain Technology
    • Blockchain Developments
    • Blockchain Security
    • Layer 2 Solutions
    • Smart Contracts
  • Interviews
    • Crypto Investor Interviews
    • Developer Interviews
    • Founder Interviews
    • Industry Leader Insights
  • Regulations & Policies
    • Country-Specific Regulations
    • Crypto Taxation
    • Global Regulations
    • Government Policies
  • Learn
    • Crypto for Beginners
    • DeFi Guides
    • NFT Guides
    • Staking Guides
    • Trading Strategies
  • Research & Analysis
    • Blockchain Research
    • Coin Research
    • DeFi Research
    • Market Analysis
    • Regulation Reports
Have an existing account? Sign In
Follow US
© Market Alert News. All Rights Reserved.
  • bitcoinBitcoin(BTC)$75,845.00-1.58%
  • ethereumEthereum(ETH)$2,355.44-2.74%
  • tetherTether(USDT)$1.000.00%
  • rippleXRP(XRP)$1.44-2.50%
  • binancecoinBNB(BNB)$631.09-1.88%
  • usd-coinUSDC(USDC)$1.000.03%
  • solanaSolana(SOL)$86.32-2.68%
  • tronTRON(TRX)$0.3295090.54%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.041.31%
  • dogecoinDogecoin(DOGE)$0.095020-4.42%
Interviews

Russian Hackers Exploit WinRAR Zero-Day

Last updated: August 13, 2025 2:40 am
Published: 8 months ago
Share

RomCom Group Deployed SnipBot, RustyClaw and Mythic Agent Variants

A Russian speaking hacking group is exploiting a zero-day flaw in WinRAR, a sign of the group’s growing sophistication and evolution from a cybercrime outfit into a cyberespionage operation.

See Also: OnDemand | North Korea’s Secret IT Army and How to Combat It

Researchers at security firm Eset uncovered the campaign, which has been active since July. The campaign exploited a vulnerability now tracked as CVE-2025-8088, a path traversal vulnerability. WinRAR published a patch July 31 after Eset researchers alerted the company.

RomCom, also tracked as Storm-0978, Tropical Scorpius and UNC2596, mainly deployed ransomware in the past. Since Russia’s 2022 invasion of Ukraine, the group has conducted cyberespionage operations aligned with Kremlin interests, along with conventional cybercrime operations. “This is at least the third time RomCom has used a zero-day vulnerability in the wild, highlighting its ongoing focus on acquiring and using exploits for targeted attacks,” Eset researchers said about the latest campaign.

It begins with phishing emails disguised as job applications. Hackers took advantage of the alternate data stream attribute in the Windows NTFS file system to embed malicious code that WinRAR automatically unpacked. Attackers use multiple alternate data stream entries with dummy data and invalid paths to hide their payloads.

Researchers observed three infection chains deploying different malware:

“The discovered campaign targeted sectors that align with the typical interests of Russian-aligned APT groups, suggesting a geopolitical motivation behind the operation,” Eset researchers said.

In addition to RomCom, another threat group tracked as Paper Werewolf and Goffee is exploiting the WinRAR flaw to target Russian companies, Moscow-based Bi.zone said.

Hacking campaigns using job impersonation were previously a hallmark of North Korean hackers, but cybercriminals across the world now deploy the same tactic (see: North Korean Hackers Spreading Malware Via Fake Interviews).

Read more on DataBreachToday

This news is powered by DataBreachToday DataBreachToday

Share this:

  • Share on X (Opens in new window) X
  • Share on Facebook (Opens in new window) Facebook

Like this:

Like Loading...

Related

Enhancing Health Sciences Master’s with Evidence-Based Practices
Day six in court: Defendants in Bommeleeër II trial explain past statements
US teen pilot claims innocence after charges dropped in Antarctica flight case
Democrats frustration with their party sees sharp increase, poll shows
Nandy apologises for donor link error in football watchdog appointment

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Email Copy Link Print
Previous Article US grand jury indicts one of Haiti’s most powerful gang leaders and one of his friends
Next Article Ralph Lauren Collection Aims to Celebrate Oak Bluffs Black Community
© Market Alert News. All Rights Reserved.
Welcome Back!

Sign in to your account

Username or Email Address
Password

Prove your humanity


Lost your password?

%d