Two Russian cybercrime groups, RomCom and Paper Werewolf, exploited a zero-day vulnerability (CVE-2025-8088) in WinRAR, a widely used file compressor. The attacks involved malicious archives attached to personalized phishing emails, allowing the attackers to execute code on victim's computers. ESET detected the attacks on July 18th and notified WinRAR developers, resulting in a patch release on July 30th. This is at least the third zero-day exploit used by RomCom, demonstrating their significant resources and sophisticated techniques.
Prepared by Jonathan Pierce and reviewed by editorial team.
Comments