{"id":7449,"date":"2025-08-25T15:18:56","date_gmt":"2025-08-25T12:18:56","guid":{"rendered":"https:\/\/blog.eset.ee\/et\/?p=7449"},"modified":"2026-06-14T10:24:48","modified_gmt":"2026-06-14T07:24:48","slug":"eset-research-russian-romcom-group-exploits-new-vulnerability-targets-companies-in-europe-and-canada","status":"publish","type":"post","link":"https:\/\/blog.eset.ee\/et\/en\/2025\/08\/25\/eset-research-russian-romcom-group-exploits-new-vulnerability-targets-companies-in-europe-and-canada\/","title":{"rendered":"ESET Research: Russian RomCom group exploits new vulnerability, targets companies in Europe and Canada"},"content":{"rendered":"<p><!\u2013 wp:list \u2013><\/p>\n<ul class=\"wp-block-list\"><!\u2013 wp:list-item \u2013><\/p>\n<li>If you use WinRAR or other affected components such as the Windows versions of its command line utilities, UnRAR.dll, or the portable UnRAR source code, upgrade immediately to the latest version.<\/li>\n<p><!\u2013 \/wp:list-item \u2013><\/p>\n<p><!\u2013 wp:list-item \u2013><\/p>\n<li>ESET researchers have discovered a previously unknown zero-day vulnerability in WinRAR being exploited in the wild by Russia-aligned group RomCom<\/li>\n<p><!\u2013 \/wp:list-item \u2013><\/p>\n<p><!\u2013 wp:list-item \u2013><\/p>\n<li>Analysis of the exploit led to the discovery of the vulnerability, now assigned CVE-2025-8088: a path traversal vulnerability, made possible with the use of alternate data streams. After notification, WinRAR released a patched version on July 30th, 2025.<\/li>\n<p><!\u2013 \/wp:list-item \u2013><\/p>\n<p><!\u2013 wp:list-item \u2013><\/p>\n<li>Successful exploitation attempts delivered various backdoors used by the RomCom group, specifically a SnipBot variant, RustyClaw, and the Mythic agent.<\/li>\n<p><!\u2013 \/wp:list-item \u2013><\/p>\n<p><!\u2013 wp:list-item \u2013><\/p>\n<li>This campaign targeted financial, manufacturing, defense, and logistics companies in Europe and Canada.<\/li>\n<p><!\u2013 \/wp:list-item \u2013><\/ul>\n<p><!\u2013 \/wp:list \u2013><\/p>\n<p><!\u2013 wp:paragraph \u2013><\/p>\n<p><strong>BRATISLAVA<\/strong>\u00a0\u2014\u00a0<strong>August, 2025<\/strong>\u00a0\u2014 ESET researchers have discovered a previously unknown vulnerability in WinRAR, exploited in the wild by Russia-aligned group RomCom. According to ESET telemetry, malicious archives were used in spearphishing campaigns between July 18 to July 21, 2025, targeting financial, manufacturing, defense, and logistics companies in Europe and Canada. The aim of the attacks was cyberespionage. This is at least the third time that RomCom has been caught exploiting a significant zero-day vulnerability in the wild<\/p>\n<p><!\u2013 \/wp:paragraph \u2013><\/p>\n<p><!\u2013 wp:paragraph \u2013><\/p>\n<p>\u201cOn July 18, we observed a malicious DLL named msedge.dll in a RAR archive containing unusual paths that caught our attention. Upon further analysis, we found that the attackers were exploiting a previously unknown vulnerability affecting WinRAR, including the then-current version 7.12. On July 24, we contacted the developer of WinRAR; the same day the vulnerability was fixed in beta version with a full version released few days later. We advise WinRAR users to install the latest version as soon as possible to mitigate the risk,\u201d says ESET researcher Peter Str\u00fd\u010dek who made the discovery along with another ESET researcher Anton Cherepanov. The vulnerability, CVE-2025-8088, is a path traversal vulnerability, which is made possible via the use of alternate data streams.<\/p>\n<p><!\u2013 \/wp:paragraph \u2013><\/p>\n<p><!\u2013 wp:paragraph \u2013><\/p>\n<p>Disguised as an application document, the weaponized archives exploited a path traversal flow to compromise its targets. In the spearphishing email, the attackers sent a CV hoping that a curious target would open it. According to ESET telemetry, none of the targets were compromised. The attackers, however, had conducted reconnaissance beforehand and the emails were highly targeted. Successful exploitation attempts delivered various backdoors used by RomCom group \u2013 specifically, a SnipBot variant, RustyClaw, and the Mythic agent.<\/p>\n<p><!\u2013 \/wp:paragraph \u2013><\/p>\n<p><!\u2013 wp:paragraph \u2013><\/p>\n<p>ESET Research attributes the observed activities to RomCom with high confidence based on the targeted region, tactics, techniques, and procedures&nbsp; (TTPs), and the malware used. RomCom (also known as Storm-0978, Tropical Scorpius, or UNC2596) is a Russia-aligned group that conducts both opportunistic campaigns against selected business verticals and targeted espionage operations. The group\u2019s focus has shifted to include espionage operations collecting intelligence, in parallel with its more conventional cybercrime operations. The backdoor used by the group is capable of executing commands and downloading additional modules to the victim\u2019s machine. It is not the first time that RomCom has used exploits to compromise its victims. In 2023-06, the group performed a spearphishing campaign targeting defense and governmental entities in Europe, with lures related to the Ukrainian World Congress.<\/p>\n<p><!\u2013 \/wp:paragraph \u2013><\/p>\n<p><!\u2013 wp:paragraph \u2013><\/p>\n<p>\u201cBy exploiting a previously unknown zero-day vulnerability in WinRAR, the RomCom group has shown that it is willing to invest serious effort and resources into its cyberoperations. The discovered campaign targeted sectors that align with the typical interests of Russian-aligned APT groups, suggesting a geopolitical motivation behind the operation,\u201d concludes Str\u00fd\u010dek.<\/p>\n<p><!\u2013 \/wp:paragraph \u2013><\/p>\n<p><!\u2013 wp:paragraph \u2013><\/p>\n<p>For a more detailed analysis and technical breakdown of RomCom\u2019s latest campaign, check out the latest ESET Research blogpost \u201c<a href=\"https:\/\/www.welivesecurity.com\/en\/eset-research\/update-winrar-tools-now-romcom-and-others-exploiting-zero-day-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">RomCom exploits a new vulnerability in the wild, this time in WinRAR<\/a>\u201d on WeLiveSecurity.com. Make sure to follow&nbsp;<a href=\"https:\/\/twitter.com\/ESETresearch\" target=\"_blank\" rel=\"noreferrer noopener\">ESET Research on Twitter (today known as X)<\/a>,&nbsp;<a href=\"https:\/\/bsky.app\/profile\/esetresearch.bsky.social\" target=\"_blank\" rel=\"noreferrer noopener\">BlueSky<\/a>, and&nbsp;<a href=\"https:\/\/infosec.exchange\/@ESETresearch\" target=\"_blank\" rel=\"noreferrer noopener\">Mastodon<\/a>&nbsp;for the latest news from ESET Research.<\/p>\n<p><!\u2013 \/wp:paragraph \u2013><\/p>\n","protected":false},"excerpt":{"rendered":"<p>If you use WinRAR or other affected components such as the Windows versions of its command line utilities, UnRAR.dll, or the portable UnRAR source code, upgrade immediately to the latest version. ESET researchers have discovered a previously unknown zero-day vulnerability in WinRAR being exploited in the wild by Russia-aligned group RomCom Analysis of the exploit [&hellip;]<\/p>\n","protected":false},"author":5,"featured_media":7453,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[2880],"tags":[],"class_list":["post-7449","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-digital-security"],"acf":[],"amp_enabled":true,"_links":{"self":[{"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/posts\/7449","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/comments?post=7449"}],"version-history":[{"count":0,"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/posts\/7449\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/media\/7453"}],"wp:attachment":[{"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/media?parent=7449"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/categories?post=7449"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/tags?post=7449"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}