Certain versions of the WinRAR file compression tool and Winbox software have been compromised and are being used to install malware . According to research , this spyware distribution campaign probably began in the second half of 2018 but is still ongoing. The campaign comes from the StrongPity group , which specializes in so-called watering hole attacks aimed at espionage.
The StrongPity group, also known as Promethium, first gained attention in 2016 when it used websites to distribute trojanized versions of WinRAR and TrueCrypt. However, it has been active since 2012. It has repeatedly used zero-day vulnerabilities in spear-phishing attacks.
AT&T Alien Labs researchers have discovered a new malware a few days ago . It was installed by a trojanized but fully functional copy of Winbox ( sample analysis ) for Windows systems.
There was no difference in operation to make the victims suspect that something was wrong.

Newer versions of the popular WinRAR program (sample analysis) and Internet Download Manager (sample analysis) are also used to install spyware by the StrongPity group.
The spyware searches for documents and communicates with the command and control server via an SSL connection . It also provides remote access. , according to a report by the researchers
In the past, hackers have used other popular software to install malware. Some of them are: CCleaner, Driver Booster, Opera Browser, Skype and VLC Media Player, Antivirus and 7-Zip.
The hacker group appears to be using methods and techniquesthat it has used in other campaigns to distribute malware. In December 2017, ESET reported on a StrongPity campaign targeting an Internet service provider.
StrongPity targeted some victims and when they tried to download the software (which they considered legitimate), they were redirected to the malicious version.
