WinRAR Woes: Exploited Zero-Day Bug Opens Door for RomCom Malware Mayhem
WinRAR’s new slogan: “Opening doors you never knew you had!” The WinRAR vulnerability, CVE-2025-8088, was exploited in phishing attacks to install RomCom malware. Upgrade to WinRAR 7.13 now, unless you like surprise startup programs.

Hot Take:
WinRAR: The OG of file compression just got a dose of drama it didn’t ask for. Who knew opening a simple archive could lead to a Russian cyber dance party in your startup folder? Time to update or be prepared for an unexpected malware waltz!
Key Points:
- A WinRAR vulnerability, CVE-2025-8088, was exploited as a zero-day.
- The flaw allows for directory traversal, letting attackers choose file extraction paths.
- RomCom malware, linked to Russian hackers, spread through phishing attacks using this flaw.
- The vulnerability is patched in WinRAR 7.13, but requires manual updating by users.
- ESET discovered the vulnerability and is preparing a detailed report.
Already a member? Log in here