Analysis of Gamaredon campaign targeting Ukraine weaponizing CVE-2025-8088
June 19, 2026, 8:39 a.m.
Description
A campaign exploiting the WinRAR path-traversal vulnerability CVE-2025-8088 has been actively targeting Ukraine since February 2026, with ongoing activity through June 2026. The operation uses Ukrainian military and conscription-themed documents as lures, distributed as RAR archives. The malicious archives contain NTFS alternate data streams with path-traversal sequences that automatically place LNK files into the Windows Startup folder upon extraction. These shortcuts execute hidden PowerShell stagers incorporating anti-analysis techniques including debugger checks, disk-space verification, and sleep delays to evade sandbox detection. The persistent nature of the attacks demonstrates continuous targeting of Ukrainian entities over a four-month period using social engineering focused on military documentation themes.
Tags
Date
- Created: June 19, 2026, 4:31 a.m.
- Published: June 19, 2026, 4:31 a.m.
- Modified: June 19, 2026, 8:39 a.m.
Indicators
- cb65f5873c72d707371ec56fb8ba501a5c7f5940e9c5a2d28c9b379ce216900c
- 507b2fcdae058cebbd550965b90c44e878d7a2463058c846eeb68f0dc1b48eda
- bf338d88f60c0d352cd0d1b5e4bc6a1d9f1ac8fe1df48516ec0042cafda821e9
- 2add9429d2822ae0c01c08bbd66c3a110ef2e9c3a00cded1477657e9024e391e
- 1c170b7470d507378ddb78e9d66305f1184e965baaf2d27ededb23a318a58953
- 1ebbdf3671cd5ca25a8a8e7ca2f6e46dd22c631e01bfcc5c909ae2fd680bf458
- f668bd551859007cf2cc2a62bf0bf5414870a04e9782590c9bf85c849ddb308b
- f9d2907d6b1de3078a0f111cc98764a92baf5ebd06cc8ab02637a65eff3b7f3a
- 0a9bc91e7ea2c3931f662eea37c00c7c26c8996b65f6f7afe6cce8f6114f94b6
- 39dd1bd3bccc314d8933e5c41ed2ab084e4e20af569f77b7cf09abc5855b9483
Additional Informations
- Defense
- Government
- Ukraine