
Following the discovery of the WinRAR, a new ransomware, which exploits the vulnerability to spread to Windows computers, demanding a ransom from their owners.
Specifically, this new ransomware exploits a vulnerability that was only recently discovered by security researchers in the WinRAR ACE code, despite the fact that it has existed for the past 19 years. The WinRAR library UNACEV2.DLL is the one affected.
WinRAR is the most popular file compression tool in the world, used by over 500 million users.
Since its discovery, the vulnerability has been patched. However, hackers continue to exploit vulnerabilities on systems that have not been updated with the appropriate patch.
The payload of JNEC.a Ransomware is stored in a RAR file archive. Once the victim decompresses the archive, a corrupted female image opens. In this way, JNEC.a Ransomware enters the victim’s system and begins the process of encrypting files and locking the system.
In order for users to obtain the decryption key that will unlock their files, they must pay the requested amount to an email ID provided by the hackers.
The discovery of a sample of the JNEC.a Ransomware named (vk_4221345.rar) was made by researchers at the 360 Threat Intelligence Center, who confirmed that the ransomware spread through a vulnerability in WinRAR (# CVE-2018-20250).
Once the ransomware is successfully installed, it begins locking files on the victim's computer and displays a message demanding a ransom in bitcoins and presenting the steps the user must follow to obtain the decryption key.
In this case, victims must create a specific mailbox for their Gmail ID so they can receive the decryption key.
The attackers demand 0.05 BTC ($198 USD) from each victim of the JNEC.a Ransomware and will contact them once they receive the payment.
All WinRAR users are advised to update to the current version, WinRAR 5.70 to be safe from such attacks and should also avoid opening unknown files.
