Gallery

Contacts

405 W. Greenlawn Ave Lansing, Michigan 48910

contact@techjacksolutions.com

+1-616-320-4064

Russia’s FSB-linked Gamaredon group is actively exploiting a path traversal vulnerability in WinRAR (CVE-2025-8088, CVSS 7.5) to deliver a four-stage malware chain against Ukrainian government, military, and critical infrastructure organizations. The attack chain deploys tools for initial access, persistence, lateral movement, and data exfiltration, with stolen files staged to AWS S3 buckets and command-and-control routed through Telegram to evade detection. Organizations outside Ukraine with Ukrainian government or defense sector supply chain relationships, or those running unpatched WinRAR, carry meaningful exposure to this campaign.

Author

Tech Jacks Solutions