Listen to this Post

Introduction
In a startling revelation, BI.ZONE Threat Intelligence has uncovered a highly sophisticated cyberattack campaign orchestrated by the Paper Werewolf (GOFFEE) threat actor cluster. Exploiting both a publicly known vulnerability and a previously unknown zero-day flaw in WinRAR archiving software, the attackers demonstrated advanced techniques capable of bypassing modern security defenses. This campaign, discovered in July 2025, focused primarily on Russian organizations, leveraging phishing emails and malicious archives to infiltrate systems undetected. The discovery underscores the ongoing risks posed by archive-based malware delivery and emphasizes the importance of timely patching and proactive threat monitoring.
Dual-Stage Attack Summary
The initial attack wave exploited CVE-2025-6218, a directory traversal vulnerability affecting WinRAR versions up to 7.11. Attackers impersonated staff from Russian R\&D institutes and government ministries, sending malicious RAR files from compromised email accounts. Files like minprom_04072025.rar executed code outside the target directory, placing the malicious executable xpsrchvw74.exe into the Windows startup folder. This executable, a modified XPS Viewer with embedded shellcode, established a reverse shell to a command-and-control server, using ROR13 hashing to obfuscate critical Windows API functions.
A second, more alarming stage involved a previously unknown zero-day vulnerability impacting WinRAR versions up to 7.12. This flaw exploited the software’s handling of alternative data streams (ADS), allowing attackers to write arbitrary payloads into system directories. Malicious archives like Запрос_Минпромторг_22.07.rar delivered WinRunApp.exe loaders and created startup shortcuts while victims interacted with decoy PDF files. The C loader ensured persistence through mutex creation and continued attempts to fetch additional payloads from compromised domains such as IndoorVisions[.]org.
Evidence also points to potential underground marketplace involvement. Forum posts advertised a working WinRAR zero-day exploit for \$80,000, suggesting that Paper Werewolf may have purchased and adapted exploit code from cybercriminal sources. Following collaboration between ESET specialists and WinRAR developers, the vulnerability was patched in version 7.13. Indicators of compromise include MD5, SHA1, and SHA256 hashes of malicious files and executables, critical for detecting infections. This dual-stage campaign demonstrates the continued effectiveness of archive-based malware in bypassing email security systems and reinforces the importance of comprehensive software and security monitoring practices.
What Undercode Say:
The Paper Werewolf campaign represents a sophisticated evolution in targeted cyberattacks, combining social engineering, exploitation of known vulnerabilities, and novel zero-day techniques. The strategic use of malicious archives indicates the group’s deep understanding of operational security gaps within organizations. By leveraging legitimate-looking email accounts and impersonating trusted entities, the attackers increase the likelihood of victims executing the malicious files without suspicion.
The exploitation of CVE-2025-6218 shows how traditional vulnerabilities, even if publicly disclosed, continue to pose a risk when organizations delay patching. The directory traversal technique used demonstrates that attackers are not just aiming for immediate compromise but are carefully positioning malicious payloads to persist and evade standard detection. ROR13 hashing of Windows API function calls highlights advanced anti-analysis measures, making the malware resilient against automated defense mechanisms.
The zero-day vulnerability discovery in ADS handling points to an alarming escalation. Attackers exploit fundamental aspects of file system management, allowing payloads to embed deep into system directories. The creation of mutex objects and persistent loaders ensures long-term access to compromised systems, reflecting strategic intent beyond immediate theft or disruption.
Connections to underground marketplaces indicate a growing commercialization of exploits. While direct links are not fully confirmed, the timing and nature of attacks strongly suggest that threat actors can acquire and adapt zero-day exploits for targeted campaigns. This hybrid approach—combining purchased vulnerabilities with internal attack engineering—represents a significant threat model for organizations, especially those handling sensitive governmental or research data.
Moreover, the campaign underlines a broader cybersecurity lesson: archiving software, often considered low-risk, can be weaponized effectively. Organizations must treat all software components as potential attack surfaces, implementing layered defenses and monitoring unusual system behaviors. From a defense perspective, the campaign reinforces the importance of routine threat hunting, endpoint monitoring, and timely vulnerability patching. Proactive measures such as scanning for ADS manipulations, monitoring for unusual startup folder changes, and tracking outbound connections to suspicious domains are essential to detect and mitigate such sophisticated attacks.
The malware’s design, with both obfuscation and persistence mechanisms, demonstrates the evolving sophistication of threat actors who increasingly blur the line between conventional malware and advanced persistent threats (APTs). This campaign is an example of how a single software vulnerability, when combined with social engineering and underground exploit trading, can create disproportionate risk to high-value targets.
🔍 Fact Checker Results
BI.ZONE identified the campaign ✅
Exploited CVE-2025-6218 and a zero-day ✅
Attack connected to underground marketplaces ❌ (unconfirmed)
📊 Prediction
Given the trend observed in the Paper Werewolf campaign, it is likely that archive-based malware attacks will continue to grow in sophistication, particularly against research institutions and governmental organizations. Expect increased targeting of file-handling software, more rapid adaptation of purchased zero-day exploits, and broader integration of social engineering techniques. Organizations that delay patching or underestimate the risks of legacy software will remain high-value targets, emphasizing the need for continuous security audits, proactive threat hunting, and rigorous software update policies.
If you want, I can also create a clickbait-style, SEO-optimized title specifically designed to dramatically increase reader engagement for this article. Do you want me to do that?
🕵️📝✔️Let’s dive deep and fact‑check.
References:
Reported By: cyberpress.org
Extra Source Hub:
https://www.quora.com/topic/Technology
Wikipedia
OpenAi & Undercode AI
Image Source:
Unsplash
Undercode AI DI v2
🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]
📢 Follow UndercodeNews & Stay Tuned:
𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon




