Реклама партнера — Название партнёра
UNIT.City — місце, де люди працюють... КРАЩЕ! Обирай свій простір просто зараз 👉

Russian hackers use WinRar vulnerability to attack Ukrainian users

Google cyber experts have reported that several hackers, including those supported by state agencies, are exploiting a critical vulnerability in RARLAB’s WinRAR to gain access to users' files.

Leave a comment
Russian hackers use WinRar vulnerability to attack Ukrainian users

Google cyber experts have reported that several hackers, including those supported by state agencies, are exploiting a critical vulnerability in RARLAB’s WinRAR to gain access to users' files.

«Discovered and patched in July 2025, the vulnerability continues to be exploited in various operations by attackers linked to Russia and China, as well as attackers with financial motives», said experts from the Google Threat Intelligence Group (GTIG).

Hacker News reports that this path traversal vulnerability allows files to be placed in the Windows startup folder. This flaw was fixed in WinRAR version 7.13, released on July 30, 2025. However, in unpatched versions, the vulnerability allows hackers to execute arbitrary code by creating malicious archive files.

ESET, which discovered and reported this security flaw, said it had observed a dual financial and espionage group known as RomCom (also known as CIGAR or UNC4895) exploiting this vulnerability as early as July 18, 2025.

It is noted that Russian hackers from Sandworm used this vulnerability to «place a decoy file with a Ukrainian name» and a malicious LNK file that attempts to download additional files. And Russians from Gamaredon carried out attacks on Ukrainian government institutions using malicious RAR archives containing HTML Application (HTA) files.

Turla attackers are also mentioned as having exploited this vulnerability to infect computers with the STOCKSTAY malware. They used «deception» related to Ukraine’s military activities and drone operations.

Read the country's main IT news in our Telegram
Read the country’s main IT news in our Telegram
On the topic
Read the country’s main IT news in our Telegram
Russian hacking group RomCom exploited new vulnerability in WinRAR to attack companies around the world
Russian hacking group RomCom exploited new vulnerability in WinRAR to attack companies around the world
On the topic
Russian hacking group RomCom exploited new vulnerability in WinRAR to attack companies around the world
Members of a hacker group linked to the Russian Federation were exposed in Ukraine
Members of a hacker group linked to the Russian Federation were exposed in Ukraine
On the topic
Members of a hacker group linked to the Russian Federation were exposed in Ukraine
North Korean hackers stole a record $2 billion in crypto in 2025
North Korean hackers stole a record $2 billion in crypto in 2025
On the topic
North Korean hackers stole a record $2 billion in crypto in 2025

Have important news to share? Message our Telegram bot

Key events and useful links in our Telegram channel

Discussion
No comments yet.