{"id":60823,"date":"2026-06-08T00:00:00","date_gmt":"2026-06-08T00:00:00","guid":{"rendered":"urn:uuid:655fdcea-cfd6-6a9e-fe45-9d552a77be50"},"modified":"2026-06-08T00:00:00","modified_gmt":"2026-06-08T00:00:00","slug":"old-winrar-flaw-fuels-attacks-on-ukraine-how-unmanaged-software-keeps-the-door-open","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/old-winrar-flaw-fuels-attacks-on-ukraine-how-unmanaged-software-keeps-the-door-open\/","title":{"rendered":"Old WinRAR Flaw Fuels Attacks on Ukraine: How Unmanaged Software Keeps the Door Open"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/trendmicro.scene7.com\/is\/image\/trendmicro\/ukraine-vulnerability-cover:Large?qlt=80\"><\/p>\n<div><img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/thumbnails\/26\/f\/ukraine-vulnerability-cover.jpg\" class=\"ff-og-image-inserted\"><\/div>\n<h2><span class=\"body-subhead-title\"><\/span><\/h2>\n<p>We track the binary payload chain (CVE-2025-8088 to LNK to PowerShell to <i>result.dll<\/i>) under <b>SHADOW-EARTH-066<\/b>, our temporary designation for the intrusion set that CERT-UA tracks as <a href=\"https:\/\/cert.gov.ua\/article\/6282946\">UAC-0226<\/a>.<\/p>\n<p>The attribution to UAC-0226 is based on the malware lineage. Our analysis confirms that <i>result.dll<\/i> is a direct evolution of GIFTEDCROOK, the stealer that CERT-UA attributed to UAC-0226 in April 2025. The two share the same compiler toolchain, cryptographic framework, anti-analysis checks, and exfiltration protocol, as detailed in the evolution comparison above.<\/p>\n<p>Timestamp analysis provides an additional attribution data point. All LNK files share the same creation timestamp and builder machine identifier (desktop-hagd25b), confirming a single build environment. The PE compile timestamps of four distinct DLL builds (February 3, February 17, March 16, and April 9, 2026) cluster between 06:33 and 11:32 UTC. RAR archive timestamps for the packaged decoy PDFs independently corroborate these build sessions, aligning within seconds of the corresponding PE compile times.<\/p>\n<p>Mapped to UTC+3 (Moscow time), these correspond to 09:33\u201314:32 local time. All six build events fall on weekdays. While these timestamps can be manipulated, the consistent weekday pattern across multiple sources and the alignment with UTC+3 working hours suggest an operator based near that time zone.<\/p>\n<h2><span class=\"body-subhead-title\"><\/span><\/h2>\n<p>We attribute the HTA-based infection chain to <b>Earth Dahu<\/b> (Gamaredon) with <b>high confidence<\/b>. This assessment is based on:<\/p>\n<ul>\n<li><span class=\"rte-red-bullet\"><b>Direct continuity<\/b>: The HTA chain is a continuation of the campaign we reported in the APT Research Report (which is available to subscribers of the Trend Vision One\u2122 Threat Intelligence Hub). The exploitation method, post-exploitation chain (HTA to VBScript to espionage modules), and C&amp;C infrastructure pattern (Dynamic DNS with Cloudflare Workers) are identical.<\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>TTP consistency<\/b>: The spear-phishing delivery TTPs match established Earth Dahu patterns, including compromising government email accounts, BCC self-addressed distribution, and C&amp;C proxying through Cloudflare Workers.<\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>Victimology<\/b>: Exclusive targeting of Ukrainian government and military entities is consistent with Earth Dahu\u2019s documented operational mandate.<\/span><\/li>\n<\/ul>\n<h2><span class=\"body-subhead-title\"><\/span><\/h2>\n<p>The two campaigns examined in this report share the same initial exploit (CVE-2025-8088) and overlapping victimology, but the post-exploitation chains are fundamentally different:<\/p>\n<ul>\n<li><span class=\"rte-red-bullet\">SHADOW-EARTH-066 communicates with <b>direct IP-based C&amp;C servers<\/b> and delivers a <b>compiled x86-64 DLL<\/b> with PEB-walk API resolution and RC4-encrypted strings. Earth Dahu uses <b>Cloudflare Workers<\/b> as a C&amp;C proxy and relies on <b>script-based tooling<\/b> (HTA, VBScript, PowerShell).<\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>No shared infrastructure<\/b> has been identified between the two campaigns.<\/span><\/li>\n<\/ul>\n<p>The tooling reflects different development traditions: the GIFTEDCROOK family is a compiled C++ codebase with statically linked libcurl. Earth Dahu has historically favored script-based approaches.<\/p>\n<p>Despite CVE-2025-8088 was patched in WinRAR 7.13 in July 2025, yet at the time of writing, multiple threat actor groups continued to build new exploit samples with fresh lure documents and use this vulnerability as a reliable initial access vector against Ukrainian organizations.<\/p>\n<p>SHADOW-EARTH-066 uses it to deploy an evolved information stealer, while Earth Dahu uses it to deliver espionage tools. Russia-aligned threat actors, including Sandworm, Turla, and Void Rabisu, have also been <a href=\"https:\/\/cloud.google.com\/blog\/ja\/topics\/threat-intelligence\/exploiting-critical-winrar-vulnerability\">reported<\/a> exploiting the same vulnerability.<\/p>\n<p>The convergence of both established state-backed groups and independently tracked clusters on a single vulnerability reflects the scale of the cyber threats that Ukraine faces. Since the full-scale invasion in 2022, the number of intrusion sets conducting operations against Ukrainian government and military networks has grown steadily, and credentials and documents stolen in these campaigns will not stay contained. Compromised accounts in military and government organizations may create downstream risks for allied nations and partners in their contact networks.<\/p>\n<p>The vulnerability works because WinRAR remains unpatched on enough endpoints to make the investment worthwhile. WinRAR does not auto-update, does not support Group Policy, and falls outside enterprise patch channels like WSUS, SCCM, or Intune. Verifying patch status across hundreds of endpoints requires third-party tools or manual auditing.<\/p>\n<p>SHADOW-EARTH-066 and Earth Dahu use different tooling and infrastructure, a compiled C++ stealer chain on one side, a script-based espionage framework on the other; but both relied on the same unpatched entry point.<\/p>\n<p>This problem is not unique to WinRAR, to Ukraine, or to these threat actors. Many utility applications, archiving tools, and file viewers share the same traits: widely installed, infrequently updated, and difficult to manage at enterprise scale. They accumulate known vulnerabilities over time, and threat actors deliberately look for them. CVE-2018-20250, a WinRAR vulnerability from 2018, was still being exploited in targeted attacks years after its disclosure. CVE-2025-8088 appears to be following the same pattern \u2014 and when threat actors find a vulnerability that works, they will keep using it until it stops working.<\/p>\n<p>Tracking and patching these applications is not optional. It is a basic requirement for reducing the attack surface that threat actors rely on.<\/p>\n<p> Read More <a href=\"https:\/\/www.trendmicro.com\/en_us\/research\/26\/f\/old-winrar-flaw-fuels-attacks-on-ukraine.html\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Two separate Russia-aligned campaigns are still exploiting the WinRAR flaw CVE-2025-8088 against Ukrainian organizations nearly a year after it was patched, showing how unmanaged software keeps an exploited entry point open long after the fix ships. Read More HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":60824,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[61],"tags":[9546,9510,9555,9509],"class_list":["post-60823","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-trendmicro","tag-trend-micro-research-apttargeted-attacks","tag-trend-micro-research-articles-news-reports","tag-trend-micro-research-exploitsvulnerabilities","tag-trend-micro-research-research"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Old WinRAR Flaw Fuels Attacks on Ukraine: How Unmanaged Software Keeps the Door Open 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/old-winrar-flaw-fuels-attacks-on-ukraine-how-unmanaged-software-keeps-the-door-open\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Old WinRAR Flaw Fuels Attacks on Ukraine: How Unmanaged Software Keeps the Door Open 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/old-winrar-flaw-fuels-attacks-on-ukraine-how-unmanaged-software-keeps-the-door-open\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2026-06-08T00:00:00+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/trendmicro.scene7.com\/is\/image\/trendmicro\/ukraine-vulnerability-cover:Large?qlt=80\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/old-winrar-flaw-fuels-attacks-on-ukraine-how-unmanaged-software-keeps-the-door-open\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/old-winrar-flaw-fuels-attacks-on-ukraine-how-unmanaged-software-keeps-the-door-open\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"Old WinRAR Flaw Fuels Attacks on Ukraine: How Unmanaged Software Keeps the Door Open\",\"datePublished\":\"2026-06-08T00:00:00+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/old-winrar-flaw-fuels-attacks-on-ukraine-how-unmanaged-software-keeps-the-door-open\\\/\"},\"wordCount\":783,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/old-winrar-flaw-fuels-attacks-on-ukraine-how-unmanaged-software-keeps-the-door-open\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/old-winrar-flaw-fuels-attacks-on-ukraine-how-unmanaged-software-keeps-the-door-open.jpg\",\"keywords\":[\"Trend Micro Research : APT&amp;Targeted Attacks\",\"Trend Micro Research : Articles, News, Reports\",\"Trend Micro Research : Exploits&amp;Vulnerabilities\",\"Trend Micro Research : Research\"],\"articleSection\":[\"TrendMicro\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/old-winrar-flaw-fuels-attacks-on-ukraine-how-unmanaged-software-keeps-the-door-open\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/old-winrar-flaw-fuels-attacks-on-ukraine-how-unmanaged-software-keeps-the-door-open\\\/\",\"name\":\"Old WinRAR Flaw Fuels Attacks on Ukraine: How Unmanaged Software Keeps the Door Open 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/old-winrar-flaw-fuels-attacks-on-ukraine-how-unmanaged-software-keeps-the-door-open\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/old-winrar-flaw-fuels-attacks-on-ukraine-how-unmanaged-software-keeps-the-door-open\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/old-winrar-flaw-fuels-attacks-on-ukraine-how-unmanaged-software-keeps-the-door-open.jpg\",\"datePublished\":\"2026-06-08T00:00:00+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/old-winrar-flaw-fuels-attacks-on-ukraine-how-unmanaged-software-keeps-the-door-open\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/old-winrar-flaw-fuels-attacks-on-ukraine-how-unmanaged-software-keeps-the-door-open\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/old-winrar-flaw-fuels-attacks-on-ukraine-how-unmanaged-software-keeps-the-door-open\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/old-winrar-flaw-fuels-attacks-on-ukraine-how-unmanaged-software-keeps-the-door-open.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/old-winrar-flaw-fuels-attacks-on-ukraine-how-unmanaged-software-keeps-the-door-open.jpg\",\"width\":976,\"height\":533},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/old-winrar-flaw-fuels-attacks-on-ukraine-how-unmanaged-software-keeps-the-door-open\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Trend Micro Research : APT&amp;Targeted Attacks\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tag\\\/trend-micro-research-apttargeted-attacks\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Old WinRAR Flaw Fuels Attacks on Ukraine: How Unmanaged Software Keeps the Door Open\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Old WinRAR Flaw Fuels Attacks on Ukraine: How Unmanaged Software Keeps the Door Open 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/old-winrar-flaw-fuels-attacks-on-ukraine-how-unmanaged-software-keeps-the-door-open\/","og_locale":"en_US","og_type":"article","og_title":"Old WinRAR Flaw Fuels Attacks on Ukraine: How Unmanaged Software Keeps the Door Open 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/old-winrar-flaw-fuels-attacks-on-ukraine-how-unmanaged-software-keeps-the-door-open\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2026-06-08T00:00:00+00:00","og_image":[{"url":"https:\/\/trendmicro.scene7.com\/is\/image\/trendmicro\/ukraine-vulnerability-cover:Large?qlt=80","type":"","width":"","height":""}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/old-winrar-flaw-fuels-attacks-on-ukraine-how-unmanaged-software-keeps-the-door-open\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/old-winrar-flaw-fuels-attacks-on-ukraine-how-unmanaged-software-keeps-the-door-open\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"Old WinRAR Flaw Fuels Attacks on Ukraine: How Unmanaged Software Keeps the Door Open","datePublished":"2026-06-08T00:00:00+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/old-winrar-flaw-fuels-attacks-on-ukraine-how-unmanaged-software-keeps-the-door-open\/"},"wordCount":783,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/old-winrar-flaw-fuels-attacks-on-ukraine-how-unmanaged-software-keeps-the-door-open\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2026\/06\/old-winrar-flaw-fuels-attacks-on-ukraine-how-unmanaged-software-keeps-the-door-open.jpg","keywords":["Trend Micro Research : APT&amp;Targeted Attacks","Trend Micro Research : Articles, News, Reports","Trend Micro Research : Exploits&amp;Vulnerabilities","Trend Micro Research : Research"],"articleSection":["TrendMicro"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/old-winrar-flaw-fuels-attacks-on-ukraine-how-unmanaged-software-keeps-the-door-open\/","url":"https:\/\/www.threatshub.org\/blog\/old-winrar-flaw-fuels-attacks-on-ukraine-how-unmanaged-software-keeps-the-door-open\/","name":"Old WinRAR Flaw Fuels Attacks on Ukraine: How Unmanaged Software Keeps the Door Open 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/old-winrar-flaw-fuels-attacks-on-ukraine-how-unmanaged-software-keeps-the-door-open\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/old-winrar-flaw-fuels-attacks-on-ukraine-how-unmanaged-software-keeps-the-door-open\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2026\/06\/old-winrar-flaw-fuels-attacks-on-ukraine-how-unmanaged-software-keeps-the-door-open.jpg","datePublished":"2026-06-08T00:00:00+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/old-winrar-flaw-fuels-attacks-on-ukraine-how-unmanaged-software-keeps-the-door-open\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/old-winrar-flaw-fuels-attacks-on-ukraine-how-unmanaged-software-keeps-the-door-open\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/old-winrar-flaw-fuels-attacks-on-ukraine-how-unmanaged-software-keeps-the-door-open\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2026\/06\/old-winrar-flaw-fuels-attacks-on-ukraine-how-unmanaged-software-keeps-the-door-open.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2026\/06\/old-winrar-flaw-fuels-attacks-on-ukraine-how-unmanaged-software-keeps-the-door-open.jpg","width":976,"height":533},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/old-winrar-flaw-fuels-attacks-on-ukraine-how-unmanaged-software-keeps-the-door-open\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"Trend Micro Research : APT&amp;Targeted Attacks","item":"https:\/\/www.threatshub.org\/blog\/tag\/trend-micro-research-apttargeted-attacks\/"},{"@type":"ListItem","position":3,"name":"Old WinRAR Flaw Fuels Attacks on Ukraine: How Unmanaged Software Keeps the Door Open"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/60823","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=60823"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/60823\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/60824"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=60823"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=60823"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=60823"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}