Russia-aligned Gamaredon (Earth Dahu) and UAC-0226 (SHADOW-EARTH-066) Exploit Patched WinRAR Path-Traversal CVE-2025-8088 (NTFS ADS) Against Ukrainian Organizations
Russia-aligned Gamaredon (Earth Dahu) and UAC-0226 (TL-2026-0723), also tracked as WinRAR NTFS ADS Path Traversal, is a high-severity software vulnerability scored CVSS 8.8, first published 2026-06-09 and last reviewed 2026-07-22. It is attributed to Gamaredon and UAC-0226 (Russia) with high confidence, affects RARLAB (win.rar GmbH) WinRAR, references 1 CVE (CVE-2025-8088), maps to 34 MITRE ATT&CK techniques (T1005, T1025, T1027), and is covered by 9 detection rules and 49 indicators of compromise.
Key facts for TL-2026-0723
- Threat ID
- TL-2026-0723
- Also known as
- WinRAR NTFS ADS Path Traversal, FSB Matryoshka (Sekoia), Operation GammaWorm
- Severity
- HIGH
- CVSS
- 8.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- 2026-06-09
- Last reviewed
- 2026-07-22
- Attribution
- Gamaredon and UAC-0226
- Attribution confidence
- HIGH
- Nation-state nexus
- Russia
- Motivation
- ESPIONAGE
- Target sectors
- government, military, defense, critical infrastructure, law enforcement, financial, manufacturing, logistics
- Target regions
- Ukraine, Europe, Canada, North America
- Detection rules
- 9
- Indicators of compromise
- 49
- Updates
- 2026-07-22 · revalidated 1× · latest source
Malware and tooling in Russia-aligned Gamaredon (Earth Dahu) and UAC-0226
Malware and tooling: GIFTEDCROOK, GammaSteel, Dead Drop Resolver (graph.org/teletype/workers.dev/supabase/Telegram), Mythic - S0699
Russia-aligned threat groups Gamaredon (Earth Dahu) and UAC-0226 (SHADOW-EARTH-066) continue exploiting CVE-2025-8088, a path-traversal flaw in WinRAR that abuses NTFS Alternate Data Streams to write files outside the extraction directory, nearly a year after WinRAR shipped a fix in July 2025. Spearphishing campaigns deliver crafted RAR archives that silently plant LNK persistence and loaders, deploying the GammaPhish/GammaLoad/GammaWorm/GammaSteel toolset and the GIFTEDCROOK stealer to harvest browser credentials and documents from Ukrainian government, military, and critical-infrastructure targets.
How Russia-aligned Gamaredon (Earth Dahu) and UAC-0226 works
CVE-2025-8088 is a directory/path-traversal vulnerability (CWE-35) in WinRAR's Windows components (WinRAR desktop app, UnRAR.dll, and portable UnRAR source) affecting versions prior to 7.13. The flaw abuses NTFS Alternate Data Streams (ADS): by embedding ADS entries whose names contain path-traversal sequences and the ADS colon separator, a specially crafted archive that appears to contain only a single benign file silently writes attacker-controlled files (DLLs, LNK shortcuts, scripts) to arbitrary locations such as %TEMP% and the per-user Startup folder during a normal extraction. Combined with a Startup-folder LNK, this yields code execution on next user logon. The vulnerability was originally discovered as a zero-day by ESET on 2025-07-18 while being exploited by the Russia-aligned RomCom group (Storm-0978) in spearphishing against financial, manufacturing, defense, and logistics organizations in Europe and Canada; WinRAR patched it in version 7.13 on 2025-07-30. NVD scores it 8.8 HIGH (CVSS 3.1).
Despite the patch, Russia-aligned groups have continued operationalizing CVE-2025-8088 against Ukraine well into 2026, exploiting the long tail of unpatched WinRAR installs in organizations where the tool is deeply embedded in daily operations. Trend Micro (researchers Hiroyuki Kakara and Feike Hacquebord) and Sekoia documented Gamaredon (tracked as Earth Dahu) incorporating the exploit from September 2025, and UAC-0226 (SHADOW-EARTH-066) using it to deliver an updated GIFTEDCROOK stealer. Sekoia's opportunistic YARA rule (deployed late December 2025) generated a dozen hits by January 2026, revealing a still-active campaign with multiple spearphishing waves against Ukrainian state institutions dating to September 2025.
The Gamaredon chain delivers a GammaPhish HTML Application (HTA) that drops a GammaLoad VBScript downloader leveraging Dead Drop Resolvers (DDR); GammaWorm establishes persistence and arbitrary code execution while GammaSteel performs comprehensive information theft with real-time file monitoring, exfiltrating data to AWS S3-compatible buckets. GammaWorm resolves live C2 nodes through DDR hosted on Telegraph/Teletype (graph.org), Cloudflare Workers subdomains, Supabase functions, trycloudflare tunnels, and public Telegram channels parsed with curl.exe. The UAC-0226/GIFTEDCROOK chain ships a decoy PDF plus three hidden ADS payloads, drops a Startup-folder LNK, spawns a PowerShell loader via cmd.exe, loads a DLL (result.dll) in memory to launch GIFTEDCROOK, and exfiltrates browser credentials/cookies and documents under 7MB modified in the last 45 days; exfiltration shifted from Telegram to dedicated C2 servers around February 2026 in alignment with Russia's blocking of Telegram. The original RomCom disclosure additionally tied CVE-2025-8088 to the Mythic agent, SnipBot variant, RustyClaw downloader, and MeltingClaw, with COM-hijacking persistence and sandbox-evasion guardrails.
MITRE ATT&CK techniques used in TL-2026-0723
Collection
T1005 Data from Local System; T1025 Data from Removable Media; T1113 Screen Capture; T1560 Archive Collected Data
Defense Evasion
T1027 Obfuscated Files or Information; T1036 Masquerading; T1070 Indicator Removal; T1140 Deobfuscate/Decode Files or Information; T1480 Execution Guardrails; T1497 Virtualization/Sandbox Evasion; T1564 Hide Artifacts; T1620 Reflective Code Loading
Exfiltration
T1041 Exfiltration Over C2 Channel; T1567 Exfiltration Over Web Service
Persistence
T1053 Scheduled Task/Job; T1546 Event Triggered Execution; T1547 Boot or Logon Autostart Execution
Execution
T1059 Command and Scripting Interpreter; T1204 User Execution
Command and Control
T1071 Application Layer Protocol; T1102 Web Service; T1573 Encrypted Channel
Discovery
T1083 File and Directory Discovery; T1087 Account Discovery; T1518 Software Discovery
Impact
Credential Access
T1552 Unsecured Credentials; T1555 Credentials from Password Stores
Initial Access
Lateral Movement
Resource Development
T1583 Acquire Infrastructure; T1587 Develop Capabilities; T1588 Obtain Capabilities; T1608 Stage Capabilities
Affected products and versions in Russia-aligned Gamaredon (Earth Dahu) and UAC-0226
- RARLAB (win.rar GmbH) — WinRAR
Vulnerable versions: < 7.13 (Windows); 7.12 and below
Fixed in: 7.13 - RARLAB (win.rar GmbH) — UnRAR.dll / portable UnRAR source
Vulnerable versions: < 7.13 (Windows components)
Fixed in: 7.13 - dtSearch — dtSearch
Vulnerable versions: < 2023.01
Fixed in: 2023.01
Remediation for Russia-aligned Gamaredon (Earth Dahu) and UAC-0226
Patches
- WinRAR 7.13 Final (released 2025-07-30) fixes the WinRAR desktop app, portable UnRAR source, and UnRAR.dll.
- dtSearch 2023.01 and later remediate the bundled-component variant.
Immediate actions
- Inventory and force-update all WinRAR / UnRAR.dll / dtSearch installations to WinRAR 7.13 or later (versions prior to 7.13 are vulnerable); WinRAR does not auto-update.
- Block the listed C2 domains and IPs at the perimeter and DNS layer, including dead-drop resolver hosts (graph.org, telegra.ph, teletype.in, *.workers.dev, *.trycloudflare.com, supabase.co function endpoints).
- Hunt for unexpected .lnk files in per-user Startup folders and unexpected DLLs in %TEMP% created by WinRAR/extraction processes.
Workarounds
- Where patching is delayed, extract untrusted archives only in isolated/sandboxed environments and inspect for ADS entries (e.g., dir /R).
- Block inbound RAR attachments at the mail gateway or detonate them in a sandbox before delivery.
Longer-term hardening
- Deploy EDR with behavioral detection for archive-extraction-spawned scripting (cmd.exe/powershell.exe/wscript.exe child processes of WinRAR.exe), in-memory DLL loading, and NTFS ADS write activity.
- Restrict execution of HTA (mshta.exe) and VBScript via attack-surface-reduction rules and application control (WDAC/AppLocker).
- Enforce centralized software management so security-critical tools like WinRAR cannot remain unpatched in production.
CVEs associated with Russia-aligned Gamaredon (Earth Dahu) and UAC-0226
Weaknesses (CWE) in Russia-aligned Gamaredon (Earth Dahu) and UAC-0226
CWE-35, CWE-22
Timeline of Russia-aligned Gamaredon (Earth Dahu) and UAC-0226
- UAC-0226's GIFTEDCROOK stealer first observed (demo build) targeting Ukrainian military innovation hubs and government, per Arctic Wolf.
- CERT-UA / The Hacker News document UAC-0226 deploying GIFTEDCROOK via macro-enabled XLSM spearphishing (CERT-UA alert #14303).
- ESET discovers CVE-2025-8088 as a WinRAR zero-day exploited in the wild by RomCom (Storm-0978) against Europe/Canada.
- ESET Research reports CVE-2025-8088 to RARLAB.
- RARLAB releases WinRAR 7.13 Final, fixing the NTFS ADS path-traversal flaw across desktop app, UnRAR.dll, and portable UnRAR source.
- CVE-2025-8088 published on NVD (CVSS 3.1 base 8.8 HIGH, CWE-35).
- Gamaredon (Earth Dahu) incorporates CVE-2025-8088 into spearphishing waves against Ukrainian state institutions.
- Sekoia deploys an opportunistic YARA rule hunting novel initial-access vectors in late December 2025.
- Sekoia's YARA rule yields a dozen hits by January 2026, surfacing the GammaPhish/GammaWorm CVE-2025-8088 campaign for in-depth investigation.
- GIFTEDCROOK exfiltration shifts from Telegram to dedicated C2 servers, aligning with Russia's blocking of Telegram.
- Earth Dahu / Gamaredon exploitation of CVE-2025-8088 confirmed still active as of April 10, 2026 (Trend Micro).
- The Hacker News reports continued Russia-aligned exploitation of CVE-2025-8088 against Ukrainian organizations.
- Malpedia publishes 'Beyond the Archive' technical analysis identifying new GIFTEDCROOK C2 infrastructure (142.111.194.73:8640 via evoxt.com) and the reflective in-memory loading chain (Main.dll!Func).
Update history for TL-2026-0723
- 2026-07-22 — CVE-2025-8088 WinRAR Path Traversal Exploited by Russia-Aligned Groups to Deploy GIFTEDCROOK Stealer Against Ukraine: What changed No severity/exploitability/status change (remains HIGH/ACTIVE/ACTIVE). New technical depth added: reflective in-memory DLL loading mechanics, new dedicated C2 infrastructure, and concrete file/path IOCs for the UAC-0226/GIFTEDC
Sources cited for Russia-aligned Gamaredon (Earth Dahu) and UAC-0226
- WinRAR Flaw Exploited by Russia-Aligned Groups (hunt source)
- Gamaredon Exploits WinRAR to Deliver GammaWorm and GammaSteel Against Ukraine
- FSB's matryoshka #1/3: Inside Gamaredon Cyber Operations — GammaPhish and GammaWorm
- Update WinRAR tools now: RomCom and others exploiting zero-day vulnerability
- NVD — CVE-2025-8088
- WinRAR zero-day was exploited by two threat actors (CVE-2025-8088)
- WinRAR Directory Traversal & NTFS ADS Vulnerabilities (CVE-2025-6218 & CVE-2025-8088)
- UAC-0226 Deploys GIFTEDCROOK Stealer via Malicious Excel Files Targeting Ukraine
- GIFTEDCROOK Malware Evolves: From Browser Stealer to Intelligence-Gathering Tool
- UAC-0226 New Cyber-Espionage Campaign with GIFTEDCROOK Stealer (CERT-UA #14303)
- WinRAR CVE-2025-8088 explained: Directory traversal enables arbitrary file writes
Threats related to Russia-aligned Gamaredon (Earth Dahu) and UAC-0226
- Gamaredon (Russia/FSB) "GammaWorm" — VBScript Worm Hidden in NTFS ADS with Cloud-Service Dead Drop Resolver C2 (Gamma Toolset) vs Ukraine, WinRAR CVE-2025-8088 Initial Access
- Gamaredon Expands Ukraine Attacks with PteroSetup Revival and Cloud Service Abuse, Exploiting WinRAR Flaw CVE-2025-8088
- Russian APT Gamaredon Upgrades Arsenal with Six New PowerShell Downloaders, Cloudflare/Devtunnel C2 Concealment, and Turla Collaboration Delivering Kazuar Backdoor (2025)
- Gamaredon (Primitive Bear / Shuckworm) APT Profile: Russia-Aligned Espionage Against Ukraine and NATO, Now Exploiting CVE-2025-8088 (WinRAR)
- Turla STOCKSTAY .NET Backdoor Targeting Ukraine Government and Military via CVE-2025-8088
- RomCom & Paper Werewolf Exploiting WinRAR CVE-2025-8088 Zero-Day via ADS Path Traversal
Detection coverage for TL-2026-0723
As of 2026-07-22, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0723 across Splunk SPL, Microsoft KQL and Sigma, covering 49 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.