Also known as: tracked as
Two Russia-aligned campaigns continue exploiting CVE-2025-8088, a WinRAR path traversal vulnerability patched in July 2025, against Ukrainian organizations through April 2026. SHADOW-EARTH-066 deploys an evolved GIFTEDCROOK information stealer using in-memory DLL loading via direct NT system calls, harvesting browser credentials, session cookies, and documents across 35 file extensions before self-deleting. Earth Dahu employs an HTA-based infection chain delivering espionage modules through Cloudflare Workers infrastructure. Both campaigns leverage the same CVE-2025-8088 exploit but use distinct tooling: SHADOW-EARTH-066 relies on compiled C++ with RC4-encrypted C&C communication, while Earth Dahu uses script-based approaches with Dynamic DNS. The persistent exploitation nearly a year post-patch demonstrates how unmanaged software lacking centralized update mechanisms creates enduring attack surfaces that threat actors deliberately target.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Shadow-Earth-066 and Earth Dahu are Russia-aligned cyber threat actors targeting Ukrainian government and defense sectors using CVE-2025-8088, a WinRAR path traversal vulnerability. Their campaigns feature advanced information-stealing tools and persistent exploitation techniques despite patch availability. The actors demonstrate high sophistication in tool development and exploit persistence.
Goals & Targeting
These actors appear to have a strategic focus on targeting乌克兰's government and defense sectors, likely to support broader Russian geopolitical objectives or to facilitate espionage activities. Their selection of Ukrainian organizations suggests an intent to gain access to sensitive information, disrupt national security, and potentially influence ongoing conflicts in the region.
Enhanced Description
Two sophisticated cyber threat actors, Shadow-Earth-066 and Earth Dahu, have been observed leveraging the CVE-2025-8088 WinRAR vulnerability to target Ukrainian organizations in an ongoing campaign. Shadow-Earth-066 deploys an evolved GIFTEDCROOK information stealer that employs in-memory DLL loading via NT system calls to harvest browser credentials, session cookies, and documents across 35 file extensions before self-deleting. In contrast, Earth Dahu utilizes an HTA-based infection chain to deliver espionage modules through Cloudflare Workers infrastructure. Both actors share the CVE-2025-8088 exploit but diverge in their tooling: Shadow-Earth-066 relies on compiled C++ with RC4-encrypted command and control communication, while Earth Dahu adopts a script-based approach with Dynamic DNS for persistence. The sustained exploitation of this vulnerability for nearly a year post-patch underscores the risks posed by unmanaged software lacking centralized update mechanisms, which create persistent attack surfaces that threat actors can exploit over extended periods. This activity aligns with Russia's historical playbook of targeting critical infrastructure and government entities in Ukraine to disrupt operations and gather strategic intelligence.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Both Shadow-Earth-066 and Earth Dahu have demonstrated a persistent attack strategy, focusing on the same vulnerability for over a year. Their campaigns highlight the importance of patch management and software update mechanisms in defending against such threats. Notable operations include targeted attacks against Ukrainian government and defense organizations from April 2025 through mid-2026.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
High confidence in the targeting patterns and technical details, as several independent reports document similar campaign activities. The actors' motivations and exact operational structure remain less clear, though their activity strongly suggests ties to Russian cyber espionage efforts.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
1
IOCs
0
Observed Data
0
Tactics