Gamaredon CVE-2025-8088 WinRAR Path Traversal HTA Drop to Startup Folder
Detects instances where WinRAR.exe is observed writing potentially malicious script or link files (.hta, .vbs, .js, .ps1, .lnk) into the Windows Startup folder. This pattern is indicative of exploitation of CVE-2025-8088, a path traversal vulnerability in WinRAR often leveraged by the Gamaredon group to establish persistence.
Microsoft Sentinel (KQL)

