CVE
CVE-2025-8088
- First Reported
- Apr 15, 2026
- Latest Reported
- Jun 25, 2026
Reported Context (2)
- year, the group also introduced a new technique – from September 26th, 2025 onward, it began abusing CVE-2025-8088, a WinRAR vulnerability, to place its usual malicious HTA downloader into the victim’s Startup folder. ESET Details Gamaredon’s 2025 Cyberespionage Tactics Against Ukraine
- backdoor. The operation relied on GitHub-hosted payloads and exploited a WinRAR vulnerability (CVE-2025-8088) to facilitate infection. Hunt.io Maps More Than 1,250 C2 Servers Across 165 Russian Providers
Malware (27)
Threat Actors (8)
MITRE ATT&CK (26)
Vendors (30)
Products (6)
Tools (12)
Industries (4)
Countries (2)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.