Uncommon Executable Written to Startup Folder by WinRAR via CVE-2025-8088 Path Traversal (via file_event)

PremiumReviewedSigma · High · v1
Product
windows
Category
file_event
Author
HuntRule
Published
2026-08-30
Updated
2026-08-30

ATT&CK techniques

Execution → Priv Esc
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Defense Evasion

  5. Cred Access

  6. Discovery

  7. Lateral Movement

  8. Collection

  9. C2

  10. Exfiltration

  11. Impact

What it detects

This rule detects WinRAR writing an executable into the user Startup folder, the persistence outcome of the CVE-2025-8088 alternate-data-stream path-traversal flaw abused in the Paper Werewolf campaign to auto-run its payload at logon. A decompression tool dropping a binary into a logon-autostart location is highly abnormal and indicates exploitation of the extractor.

Related detections9 linkedT1204.002 — drag to rearrange
Windows Startup Folder File Creation with Suspicious Script/Executable Extensions
Xeno Stealer Persistence via Display Calibration Run Key
Suspicious Node.js Script Execution from AppData Roaming
Suspicious AutoAdminLogon Enabled via Winlogon Registry by RansomHub Ransomware
Suspicious PlugX Persistence via CanonPrinter Run Key (via registry_set)
Suspicious Interlock Fake Updater Executable Execution
Malicious Office Application Loading a User-Path DLL via Regsvr32 or Rundll32 (via process_creation)
Suspicious Program Execution From a Mounted ISO or Disk Image (via process_creation)
SocGholish Fake Browser Update Script Execution (via process_creation)
Uncommon Executable Written to Startup Folder by WinRAR via CVE-2025-8088 Path Traversal (via file_event)
Pivot detection · T1204.002 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.