editor speak logo
  • Business Tech
  • Startups & VC
  • Business Insights
  • Finance & Markets
  • FutureTech
  • Enterprise & SaaS

FutureTech

WinRAR 0-Day Vulnerability Actively Exploited for Weeks by RomCom and Paper Werewolf

Munish Gupta Munish Gupta
|
Published on November 6, 2025

Currently, being taken advantage of by two Russian cybercrime groups is a major zero-day flaw in the most widely used WinRAR file compression program. Some of these attacks are customized to particular targets; they are meant to backdoor computers that open dangerous files attached to phishing emails.

ESET said on Monday that these attacks were first identified on the 18th of July when a file was found in an unusual path directory. ESET determined by July 24 that this behavior was linked to the abuse of an undetected flaw in WinRAR, a file compression application with a reported installed user base of about 500 million. On the same day, ESET notified the WinRAR developers; six days later, a patch was published.

WinRAR 0-day vulnerability exploited

Within Windows, the WinRAR 0-day vulnerability appeared to have an amazing capacity. A Windows feature that lets several forms of the same file path be used, alternate data streams were exploited here. Taking advantage of this capability, the WinRAR 0-day vulnerable exploit triggered a previously unknown path traversal bug that caused WinRAR to leave malicious executables in locations chosen by the attackers, namely %TEMP% and %LOCALAPPDATA%. Because of their capacity to run code, Windows usually blocks these locations.

Attacks that ESET linked back to RomCom, its name for a financially motivated cybercrime group operating out of Russia, have operated for many years. This well-resourced group has proved its ability to find exploits and carry out somewhat sophisticated methods. Under the number CVE-2025-8088, this group’s use of the WinRAR 0-day vulnerability is now being followed.

ESET’s Anton Cherepanov, Peter Strycek, and Damien Schaeffer remarked, “By exploiting a previously unknown WinRAR’s zero-day vulnerability, the RomCom group has shown that it is willing to invest serious effort and resources into its cyberoperations. This is at least the third time RomCom has used a zero-day vulnerability in the wild, highlighting its ongoing focus on acquiring and using exploits for targeted attacks.”Users can also read:ChatGPT to Receive OpenAI’s New Mental Health Safeguards After Reports of Harm

RECENT POSTS
Gold Prices Up as Traders Weigh Jobs Data and Shutdown…
November 14, 2025
Cloud AI Update: Microsoft Leads Cloud Computing Market Boom Toward…
November 14, 2025
$1 Trillion AI Market: AMD Targets Massive Chip Growth Plan
November 14, 2025
SoftBank Sells All Nvidia Stake Worth $5.83B to Boost AI…
November 14, 2025
PhysicsWallah’s ₹3,480-Cr IPO Opens Today After Anchor Book Nabs ₹1,563…
November 13, 2025
CATEGORIES
    • Business Insights
    • Business Tech
    • BusinessToday
    • Enterprise & SaaS
    • Finance & Markets
    • FutureTech
    • Startups & VC
  • Related Posts
    Pine Labs Ipo boost
    Pine Labs Allots Shares Worth ₹1,754 Crore to Anchor Investors…
    Pine Labs has raised ₹1,754 crore from anchor investors ahead of its... Swaraj
    nvidia and qualcomm
    NVIDIA and Qualcomm Power $1.8B Boost for India’s Deep Tech…
    Nvidia and Qualcomm have joined the India Deep Tech Alliance to boost... Swaraj
    urban company q2 fy26 37 percent revenue growth
    Urban Company’s Core Business Remains Profitable Amidst 37% Revenue Surge
    Urban Company reported a 37% year-on-year revenue surge to ₹380 crore in... Swaraj
    stampmyvisa raises 4cr ai visa
    StampMyVisa Secures ₹4 Cr to Scale AI Visa Tech and…
    Led by current supporter Unicorn India Ventures, StampMyVisa has reported the successful... Swaraj
    editor speak logo

    We deliver fast, accurate news and in-depth analysis, keeping readers updated with unbiased reports across politics, business, sports, and entertainment.

    News Categories
    • FutureTech
    • Business Insights
    • Finance & Markets
    • Business Tech
    • Business Today
    • Enterprise & SaaS
    • Startups & VC
  • Important Links
    • About Us
    • Privacy Policy
    • Correction Policy
    • Fact Checking Policy
    • Disclaimer
  • CONTACT
    • info@editorspeak.com

    Copyright © 2025 editorspeak.com