Story perspectives
Hackers Exploit WinRAR Flaw Despite July 2025 Fix
1/28/2026
25 2
1 of 1
Story summary
- Google's Threat Intelligence Group says hackers from Russia, China, and cybercrime groups are exploiting a patched WinRAR vulnerability, CVE-2025-8088, despite a July 2025 fix.
- At least seven threat actors are deploying malware via harmless-looking RAR files.
- Targeted sectors include finance and defense, with infostealers and Trojans in use.
- ISH Tecnologia notes Sandworm and China’s APT40 are among the involved actors.
- Organizations should update WinRAR to version 7.13 and bolster security measures.
