Patch WinRAR now – it’s got a major security flaw
Russian and Chinese state-sponsored threat actors have been discovered abusing a known vulnerability in the popular archiving tool WinRAR to extract sensitive information such as passwords and other login credentials.
Google’s Threat Analysis Group (TAG), which usually tracks and analyzes state-sponsored hacking players, claims to have found evidence that the flaw, identified earlier as CVE-2023-38831 by Group-IB, was being used to hide malware in archived files.
To the average Joe, the files would look like your average image, or text document. However, when downloaded and extracted, they’d infect the device with infostealing malware, capable of grabbing different files and information from the endpoint, such as passwords and payment data stored in browsers, various system information, and more.
Sandworm, APT40, and others
To make matters worse, this isn’t just one or two groups targeting WinRAR users – apparently, it’s “multiple” groups targeting “many users” who are yet to apply the patch.
The patch does exist, however, RarLab, the company behind WinRAR, released version 6.23 in early August this year, to address the issue. However, there is no way to update the program from within. Users need to head over to the WinRAR website, download the latest version, and run the installer as if they’re installing the program from scratch.
Users will want to patch, though, as one of the groups was identified as Sandworm, a Russian military intelligence unit that allegedly interfered with the 2016 presidential elections in the United States. It was also observed as quite an active player in the Russia-Ukraine war, and was behind the infamous 2017 NotPetya ransomware attack.
Another identified player is APT40, a Chinese hacking collective allegedly tied to the Chinese Ministry of State Security. It used the flaw to target endpoints in Papua New Guinea via a Dropbox link.
The WinRar vulnerability “highlights that exploits for known vulnerabilities can be highly effective”, TAG’s researchers concluded.
Via TechCrunch
More from TechRadar Pro
Russian and Chinese state-sponsored threat actors have been discovered abusing a known vulnerability in the popular archiving tool WinRAR to extract sensitive information such as passwords and other login credentials. Google’s Threat Analysis Group (TAG), which usually tracks and analyzes state-sponsored hacking players, claims to have found evidence that the…
Recent Posts
- Nintendo confirms it will sell a new Switch 2 with replaceable battery in the EU
- Apple begins requiring age verification for App Store use in Texas
- The co-creator of Scavengers Reign is working on a new show for Netflix
- Apple is bringing age verification to Texas this week
- How to watch NBA Finals 2026: Free streams, schedule, TV channels for New York Knicks vs San Antonio Spurs
Archives
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023