Analysis of Gamaredon campaign targeting Ukraine weaponizing CVE-2025-8088

June 19, 2026, 8:39 a.m.

Description

A campaign exploiting the WinRAR path-traversal vulnerability CVE-2025-8088 has been actively targeting Ukraine since February 2026, with ongoing activity through June 2026. The operation uses Ukrainian military and conscription-themed documents as lures, distributed as RAR archives. The malicious archives contain NTFS alternate data streams with path-traversal sequences that automatically place LNK files into the Windows Startup folder upon extraction. These shortcuts execute hidden PowerShell stagers incorporating anti-analysis techniques including debugger checks, disk-space verification, and sleep delays to evade sandbox detection. The persistent nature of the attacks demonstrates continuous targeting of Ukrainian entities over a four-month period using social engineering focused on military documentation themes.

Date

  • Created: June 19, 2026, 4:31 a.m.
  • Published: June 19, 2026, 4:31 a.m.
  • Modified: June 19, 2026, 8:39 a.m.

Indicators

  • cb65f5873c72d707371ec56fb8ba501a5c7f5940e9c5a2d28c9b379ce216900c
  • 507b2fcdae058cebbd550965b90c44e878d7a2463058c846eeb68f0dc1b48eda
  • bf338d88f60c0d352cd0d1b5e4bc6a1d9f1ac8fe1df48516ec0042cafda821e9
  • 2add9429d2822ae0c01c08bbd66c3a110ef2e9c3a00cded1477657e9024e391e
  • 1c170b7470d507378ddb78e9d66305f1184e965baaf2d27ededb23a318a58953
  • 1ebbdf3671cd5ca25a8a8e7ca2f6e46dd22c631e01bfcc5c909ae2fd680bf458
  • f668bd551859007cf2cc2a62bf0bf5414870a04e9782590c9bf85c849ddb308b
  • f9d2907d6b1de3078a0f111cc98764a92baf5ebd06cc8ab02637a65eff3b7f3a
  • 0a9bc91e7ea2c3931f662eea37c00c7c26c8996b65f6f7afe6cce8f6114f94b6
  • 39dd1bd3bccc314d8933e5c41ed2ab084e4e20af569f77b7cf09abc5855b9483

Attack Patterns

Additional Informations

  • Defense
  • Government
  • Ukraine

Linked vulnerabilities