🔴
CISA KEV Alert — Active Real-World Exploitation Confirmed
This vulnerability is in the CISA Known Exploited Vulnerabilities catalog and is being actively exploited right now.
Gamaredon WinRAR Vulnerability Data Theft Campaign (CVE-2025-8088) | MSSP Advisory
High🔴 KEV ALERTConfirmed
DateJune 2, 2026
CVECVE-2025-8088
CVSS Score8.8
Affectedwinrar, windows, dtsearch
Risk Assessment
Client Exposure:High
Briefing Priority:Immediate
Barrier to Entry:Low
📋Executive Summary
Russian FSB-linked group Gamaredon is actively exploiting CVE-2025-8088, a vulnerability in WinRAR, to deliver a modular malware chain beginning with a weaponized HTML Application file called GammaPhish. From there, VBScript downloaders fingerprint the host, pull arbitrary payloads from C2 servers, and deploy GammaWorm for persistence and lateral spread via malicious LNK files. GammaSteel, the information stealer in this chain, exfiltrates targeted file types to AWS S3 buckets while using Telegram for C2 communication and NTFS Alternate Data Streams to hide its components from standard detection.
⚠️Why It Matters for MSSPs
If any of your clients or your own staff open RAR attachments and WinRAR is unpatched, this chain runs quietly, fingerprints the machine, and starts pulling files before most endpoint tools catch it. The C2 traffic hides inside Telegram, which your firewall probably treats as legitimate business traffic. If GammaSteel runs in a client environment and you had not flagged a known WinRAR CVE, that is a hard conversation about whether you are actually managing their security posture.
✅Recommended Action
Audit every managed endpoint and your own internal machines for WinRAR installations within the next 24 hours, patch or remove them immediately, and send clients a direct advisory today naming CVE-2025-8088, stating that RAR archive attachments should not be opened without confirmation from the sender, and explaining that you are actively verifying patch status across their environment.
🔒Get your first advisory free →
Partner content — get access free
The recommended action is included in your white-labeled advisory — ready to send to clients under your name.
🏷️Threat Category
Nation-State
Partner MSSPs receive the full advisory — talking points, actions, and social posts — under their own brand.