A threat actor, "zeroplayer," has advertised an alleged zero-day Remote Code Execution (RCE) exploit for the WinRAR archiving software on a dark web forum. The asking price for the exploit is listed as $80,000.
On July 7, 2025, a threat actor identified as "zeroplayer" was spotted advertising an alleged zero-day exploit on the Russian-language dark web forum “Exploit.in”. The actor is offering an alleged fully functional Remote Code Execution (RCE) exploit for WinRAR. The exploit has an asking price of $80,000. In the post, "zeroplayer" emphasizes that this is a new vulnerability and is distinct from the recently patched CVE-2025-6218. As an aside, Obrela has observed a recent increase in malicious .rar and .zip archive files, which could indicate an expanded threat landscape related to archive vulnerabilities.
According to the threat actor's claims, the exploit affects the latest and all previous versions of WinRAR.