Russia-aligned Gamaredon (Earth Dahu) and UAC-0226 (SHADOW-EARTH-066) Exploit Patched WinRAR Path-Traversal CVE-2025-8088 (NTFS ADS) Against Ukrainian Organizations

Russia-aligned Gamaredon (Earth Dahu) and UAC-0226 (TL-2026-0723), also tracked as WinRAR NTFS ADS Path Traversal, is a high-severity software vulnerability scored CVSS 8.8, first published 2026-06-09 and last reviewed 2026-07-22. It is attributed to Gamaredon and UAC-0226 (Russia) with high confidence, affects RARLAB (win.rar GmbH) WinRAR, references 1 CVE (CVE-2025-8088), maps to 34 MITRE ATT&CK techniques (T1005, T1025, T1027), and is covered by 9 detection rules and 49 indicators of compromise.

Key facts for TL-2026-0723

Threat ID
TL-2026-0723
Also known as
WinRAR NTFS ADS Path Traversal, FSB Matryoshka (Sekoia), Operation GammaWorm
Severity
HIGH
CVSS
8.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Status
ACTIVE
Category
VULNERABILITY
First published
2026-06-09
Last reviewed
2026-07-22
Attribution
Gamaredon and UAC-0226
Attribution confidence
HIGH
Nation-state nexus
Russia
Motivation
ESPIONAGE
Target sectors
government, military, defense, critical infrastructure, law enforcement, financial, manufacturing, logistics
Target regions
Ukraine, Europe, Canada, North America
Detection rules
9
Indicators of compromise
49
Updates
2026-07-22 · revalidated 1× · latest source

Malware and tooling in Russia-aligned Gamaredon (Earth Dahu) and UAC-0226

Malware and tooling: GIFTEDCROOK, GammaSteel, Dead Drop Resolver (graph.org/teletype/workers.dev/supabase/Telegram), Mythic - S0699

Russia-aligned threat groups Gamaredon (Earth Dahu) and UAC-0226 (SHADOW-EARTH-066) continue exploiting CVE-2025-8088, a path-traversal flaw in WinRAR that abuses NTFS Alternate Data Streams to write files outside the extraction directory, nearly a year after WinRAR shipped a fix in July 2025. Spearphishing campaigns deliver crafted RAR archives that silently plant LNK persistence and loaders, deploying the GammaPhish/GammaLoad/GammaWorm/GammaSteel toolset and the GIFTEDCROOK stealer to harvest browser credentials and documents from Ukrainian government, military, and critical-infrastructure targets.

How Russia-aligned Gamaredon (Earth Dahu) and UAC-0226 works

CVE-2025-8088 is a directory/path-traversal vulnerability (CWE-35) in WinRAR's Windows components (WinRAR desktop app, UnRAR.dll, and portable UnRAR source) affecting versions prior to 7.13. The flaw abuses NTFS Alternate Data Streams (ADS): by embedding ADS entries whose names contain path-traversal sequences and the ADS colon separator, a specially crafted archive that appears to contain only a single benign file silently writes attacker-controlled files (DLLs, LNK shortcuts, scripts) to arbitrary locations such as %TEMP% and the per-user Startup folder during a normal extraction. Combined with a Startup-folder LNK, this yields code execution on next user logon. The vulnerability was originally discovered as a zero-day by ESET on 2025-07-18 while being exploited by the Russia-aligned RomCom group (Storm-0978) in spearphishing against financial, manufacturing, defense, and logistics organizations in Europe and Canada; WinRAR patched it in version 7.13 on 2025-07-30. NVD scores it 8.8 HIGH (CVSS 3.1).

Despite the patch, Russia-aligned groups have continued operationalizing CVE-2025-8088 against Ukraine well into 2026, exploiting the long tail of unpatched WinRAR installs in organizations where the tool is deeply embedded in daily operations. Trend Micro (researchers Hiroyuki Kakara and Feike Hacquebord) and Sekoia documented Gamaredon (tracked as Earth Dahu) incorporating the exploit from September 2025, and UAC-0226 (SHADOW-EARTH-066) using it to deliver an updated GIFTEDCROOK stealer. Sekoia's opportunistic YARA rule (deployed late December 2025) generated a dozen hits by January 2026, revealing a still-active campaign with multiple spearphishing waves against Ukrainian state institutions dating to September 2025.

The Gamaredon chain delivers a GammaPhish HTML Application (HTA) that drops a GammaLoad VBScript downloader leveraging Dead Drop Resolvers (DDR); GammaWorm establishes persistence and arbitrary code execution while GammaSteel performs comprehensive information theft with real-time file monitoring, exfiltrating data to AWS S3-compatible buckets. GammaWorm resolves live C2 nodes through DDR hosted on Telegraph/Teletype (graph.org), Cloudflare Workers subdomains, Supabase functions, trycloudflare tunnels, and public Telegram channels parsed with curl.exe. The UAC-0226/GIFTEDCROOK chain ships a decoy PDF plus three hidden ADS payloads, drops a Startup-folder LNK, spawns a PowerShell loader via cmd.exe, loads a DLL (result.dll) in memory to launch GIFTEDCROOK, and exfiltrates browser credentials/cookies and documents under 7MB modified in the last 45 days; exfiltration shifted from Telegram to dedicated C2 servers around February 2026 in alignment with Russia's blocking of Telegram. The original RomCom disclosure additionally tied CVE-2025-8088 to the Mythic agent, SnipBot variant, RustyClaw downloader, and MeltingClaw, with COM-hijacking persistence and sandbox-evasion guardrails.

MITRE ATT&CK techniques used in TL-2026-0723

Collection

T1005 Data from Local System; T1025 Data from Removable Media; T1113 Screen Capture; T1560 Archive Collected Data

Defense Evasion

T1027 Obfuscated Files or Information; T1036 Masquerading; T1070 Indicator Removal; T1140 Deobfuscate/Decode Files or Information; T1480 Execution Guardrails; T1497 Virtualization/Sandbox Evasion; T1564 Hide Artifacts; T1620 Reflective Code Loading

Exfiltration

T1041 Exfiltration Over C2 Channel; T1567 Exfiltration Over Web Service

Persistence

T1053 Scheduled Task/Job; T1546 Event Triggered Execution; T1547 Boot or Logon Autostart Execution

Execution

T1059 Command and Scripting Interpreter; T1204 User Execution

Command and Control

T1071 Application Layer Protocol; T1102 Web Service; T1573 Encrypted Channel

Discovery

T1083 File and Directory Discovery; T1087 Account Discovery; T1518 Software Discovery

Impact

T1485 Data Destruction

Credential Access

T1552 Unsecured Credentials; T1555 Credentials from Password Stores

Initial Access

T1566 Phishing

Lateral Movement

T1570 Lateral Tool Transfer

Resource Development

T1583 Acquire Infrastructure; T1587 Develop Capabilities; T1588 Obtain Capabilities; T1608 Stage Capabilities

Affected products and versions in Russia-aligned Gamaredon (Earth Dahu) and UAC-0226

  • RARLAB (win.rar GmbH) — WinRAR
    Vulnerable versions: < 7.13 (Windows); 7.12 and below
    Fixed in: 7.13
  • RARLAB (win.rar GmbH) — UnRAR.dll / portable UnRAR source
    Vulnerable versions: < 7.13 (Windows components)
    Fixed in: 7.13
  • dtSearch — dtSearch
    Vulnerable versions: < 2023.01
    Fixed in: 2023.01

Remediation for Russia-aligned Gamaredon (Earth Dahu) and UAC-0226

Patches

  • WinRAR 7.13 Final (released 2025-07-30) fixes the WinRAR desktop app, portable UnRAR source, and UnRAR.dll.
  • dtSearch 2023.01 and later remediate the bundled-component variant.

Immediate actions

  • Inventory and force-update all WinRAR / UnRAR.dll / dtSearch installations to WinRAR 7.13 or later (versions prior to 7.13 are vulnerable); WinRAR does not auto-update.
  • Block the listed C2 domains and IPs at the perimeter and DNS layer, including dead-drop resolver hosts (graph.org, telegra.ph, teletype.in, *.workers.dev, *.trycloudflare.com, supabase.co function endpoints).
  • Hunt for unexpected .lnk files in per-user Startup folders and unexpected DLLs in %TEMP% created by WinRAR/extraction processes.

Workarounds

  • Where patching is delayed, extract untrusted archives only in isolated/sandboxed environments and inspect for ADS entries (e.g., dir /R).
  • Block inbound RAR attachments at the mail gateway or detonate them in a sandbox before delivery.

Longer-term hardening

  • Deploy EDR with behavioral detection for archive-extraction-spawned scripting (cmd.exe/powershell.exe/wscript.exe child processes of WinRAR.exe), in-memory DLL loading, and NTFS ADS write activity.
  • Restrict execution of HTA (mshta.exe) and VBScript via attack-surface-reduction rules and application control (WDAC/AppLocker).
  • Enforce centralized software management so security-critical tools like WinRAR cannot remain unpatched in production.

CVEs associated with Russia-aligned Gamaredon (Earth Dahu) and UAC-0226

CVE-2025-8088

Weaknesses (CWE) in Russia-aligned Gamaredon (Earth Dahu) and UAC-0226

CWE-35, CWE-22

Timeline of Russia-aligned Gamaredon (Earth Dahu) and UAC-0226

  • UAC-0226's GIFTEDCROOK stealer first observed (demo build) targeting Ukrainian military innovation hubs and government, per Arctic Wolf.
  • CERT-UA / The Hacker News document UAC-0226 deploying GIFTEDCROOK via macro-enabled XLSM spearphishing (CERT-UA alert #14303).
  • ESET discovers CVE-2025-8088 as a WinRAR zero-day exploited in the wild by RomCom (Storm-0978) against Europe/Canada.
  • ESET Research reports CVE-2025-8088 to RARLAB.
  • RARLAB releases WinRAR 7.13 Final, fixing the NTFS ADS path-traversal flaw across desktop app, UnRAR.dll, and portable UnRAR source.
  • CVE-2025-8088 published on NVD (CVSS 3.1 base 8.8 HIGH, CWE-35).
  • Gamaredon (Earth Dahu) incorporates CVE-2025-8088 into spearphishing waves against Ukrainian state institutions.
  • Sekoia deploys an opportunistic YARA rule hunting novel initial-access vectors in late December 2025.
  • Sekoia's YARA rule yields a dozen hits by January 2026, surfacing the GammaPhish/GammaWorm CVE-2025-8088 campaign for in-depth investigation.
  • GIFTEDCROOK exfiltration shifts from Telegram to dedicated C2 servers, aligning with Russia's blocking of Telegram.
  • Earth Dahu / Gamaredon exploitation of CVE-2025-8088 confirmed still active as of April 10, 2026 (Trend Micro).
  • The Hacker News reports continued Russia-aligned exploitation of CVE-2025-8088 against Ukrainian organizations.
  • Malpedia publishes 'Beyond the Archive' technical analysis identifying new GIFTEDCROOK C2 infrastructure (142.111.194.73:8640 via evoxt.com) and the reflective in-memory loading chain (Main.dll!Func).

Update history for TL-2026-0723

Sources cited for Russia-aligned Gamaredon (Earth Dahu) and UAC-0226

Threats related to Russia-aligned Gamaredon (Earth Dahu) and UAC-0226

Detection coverage for TL-2026-0723

As of 2026-07-22, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0723 across Splunk SPL, Microsoft KQL and Sigma, covering 49 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats