New WinRAR Zero-Day Vulnerability Exploited by RomCom Group
A recently identified zero-day vulnerability in WinRAR (CVE-2025-8088) is actively being exploited by the hacking group RomCom, which is aligned with Russian interests. Insights shared by cybersecurity firm ESET reveal that this vulnerability specifically targets large enterprises worldwide, marking a significant evolution in the tactics of this group, particularly through their use of supply-chain exploits in spear-phishing attacks.
Understanding the Vulnerability
Originally reported by ESET researchers on July 18, this vulnerability functions as a path traversal exploit. It leverages Windows alternate data streams (ADSes) to hide malicious files within an innocent-looking RAR archive. When a user extracts a file that appears to be a legitimate job application or document, the malware is seamlessly deployed, often without raising any immediate alarms unless the user conducts a detailed inspection.
In response to this serious security threat, WinRAR moved quickly. A beta fix was released shortly after the discovery, and a full update was rolled out by July 30, aimed at safeguarding users against this vulnerability.
RomCom’s Use of the Vulnerability
RomCom, also known by other designations such as Storm-0978, UNC2596, or Tropical Scorpius, has now exploited its third significant zero-day in recent years. This follows their previous successes with CVE-2023-36884, which affected Microsoft Word, as well as exploits related to the Firefox-Windows zero-click chain (CVE-2024-9680 and CVE-2024-49039).
This latest campaign predominantly targets sectors such as finance, manufacturing, defense, and logistics across Europe and Canada—industries where RomCom has historically shown interest. According to security experts, the malicious archive crafted by RomCom included ADS entries that directed a DLL file to the %TEMP% directory while placing a .LNK file into the Windows Startup folder. This technique ensures persistence on infected systems through a method known as COM hijacking.
The Significance of This Threat
The widespread use of WinRAR makes this vulnerability particularly perilous; malicious archives can easily spread and be executed by unaware users.
Key Reasons for Concern
-
Efficiency of Attacks: By using targeted spear-phishing tactics featuring realistic resumes, RomCom is significantly boosting its click-through rates, especially in contexts related to hiring and recruitment.
-
Stealth Delivery: The utilization of ADS helps the malware evade casual detection. Additionally, the user interface in WinRAR obscures hidden file paths unless users delve deeper, compounding the risk.
- Operational Security (OPSEC): The rapid response from WinRAR, coupled with ESET’s swift discovery of the exploit, indicates a high level of technical competency on both sides of the issue.
These elements converge to make RomCom’s recent campaign notably impactful.
Immediate Actions for Protection
Organizations concerned about this security threat should take immediate steps to protect themselves:
-
Update WinRAR Immediately: Users should ensure that they upgrade to versions of WinRAR and its associated tools that are at least version 7.13 to mitigate risks.
-
Monitor Archive Extraction: Implement behavioral controls or use sandboxing techniques around archive extraction processes to spot unusual activities.
-
Scrutinize Job-Related Attachments: As HR processes have been increasingly weaponized, organizations should employ attachment scanning and out-of-band validation for unsolicited applications.
- Share Intelligence: The prevalence of RomCom and its use of zero-days should serve as a warning signal within the cybersecurity and intelligence communities.
RomCom’s Evolving Strategy
This recent campaign illustrates that RomCom has incorporated zero-day exploits as a fundamental part of its operations, blending cybercrime with espionage tactics effectively. Their ability to exploit WinRAR’s ADS for stealthy attacks considerably raises the threat level.
For security professionals, addressing this issue goes beyond simply applying patches. It requires robust measures to detect large-scale phishing schemes, dynamic scanning of compressed content, and effective user education regarding hidden risks associated with downloads.
RomCom’s activities highlight a concerning trend wherein even commonly used software can become conduits for state-sponsored espionage, escalating the urgency for security experts to stay vigilant against such invisible threats.


