Gamaredon and UAC-0226 Are Still Riding the WinRAR Path-Traversal Bug Into Ukrainian Networks

Nearly a year after a patch shipped, CVE-2025-8088 keeps paying dividends for two Russia-aligned crews running stealer campaigns against Ukraine.

ThreatVectr Newsdesk· 2 min read
Gamaredon and UAC-0226 Are Still Riding the WinRAR Path-Traversal Bug Into Ukrainian Networks
Share

Patched bugs don't die. They just wait for the unpatched.

Two Russia-aligned campaigns are still pushing payloads at Ukrainian targets by abusing CVE-2025-8088, a path-traversal flaw in WinRAR that lets a booby-trapped archive write files outside the directory the user thinks they're extracting to. The activity is being tracked under two cluster names: Earth Dahu, better known as Gamaredon, and a newer label, SHADOW-EARTH-066, which overlaps with the Ukrainian CERT designation UAC-0226.

The bug itself is not exotic. Path traversal in archive extractors is one of the oldest tricks in the desktop-software playbook, a close cousin of the Zip Slip class that has been kicking around since 2018. WinRAR's twist was in how alternate data streams were handled during extraction, letting a crafted RAR drop a payload into a Startup folder the victim never agreed to write to. Persistence comes free with the unzip.

A fix landed in WinRAR 7.13. Adoption, as ever, is the problem. WinRAR has no auto-update worth the name, which means a CVE from this cycle can age into a reliable access vector with very little effort from the attacker.

The targeting pattern is consistent with what Gamaredon has been doing for years: spearphish, Ukrainian government and defense-adjacent recipients, lures in Ukrainian or Russian, and a final-stage info-stealer or remote-access tool. SHADOW-EARTH-066's tradecraft is reportedly cruder but aimed at the same sector. Both clusters appear to have folded the WinRAR exploit into existing lure chains rather than building new infrastructure around it. That is the cheap, sensible move.

What makes the campaign worth flagging is less the bug than the runway. The vulnerability was originally exploited as a zero-day by RomCom and a handful of other crews before disclosure, and it has now slid into the post-patch long tail where state-aligned operators harvest whoever forgot to update. There is nothing AI-flavored about any of this. No model in the loop, no agent doing the phishing. Just a desktop utility, a path-traversal primitive, and a population of installs that nobody is centrally pushing patches to.

A few things worth doing if you run Windows fleets that touch Ukrainian partners or NGOs:

  • Inventory WinRAR installs and force-upgrade to 7.13 or later. Group Policy or your endpoint manager can do this; the installer can't.
  • Hunt for unexpected writes to per-user Startup directories originating from WinRAR.exe or its child processes over the last several months.

Gamaredon does not need novel capability to keep operating. It needs unpatched WinRAR, willing inboxes, and time. It currently has all three.

© 2026 Threat Vectr