A hacker is spreading a fake proof-of-concept (PoC) exploit for a recently patched WinRAR vulnerability on GitHub, attempting to infect downloaders with the VenomRAT malware.
Palo Alto Networks' Unit 42 research team has identified a fake PoC exploit, reporting that the attacker uploaded the malicious code to GitHub on August 21, 2023.
The attack is no longer active, but it re-emphasizes the dangers of retrieving PoCs from GitHub and executing them without additional verification to ensure their security.

Spread of WinRAR PoC
The fake PoC concerns the CVE-2023-40477 vulnerability, an arbitrary code execution vulnerability that is triggered when specially crafted RAR files are opened in WinRAR before version 6.23.
Trend Micro's Zero Day Initiative discovered and disclosed the vulnerability in WinRAR on June 8, 2023, but did not publicly disclose it until August 17, 2023. WinRAR fixed the flaw in version 6.23, which was released on August 2.
A hacker operating under the alias “whalersplonk” quickly (4 days) seized an opportunity, spreading malware by displaying exploit code for the new WinRAR vulnerability.
The perpetrator included a summary in the README file and a Streamable video demonstrating how to use the PoC, adding further legitimacy to the malicious package.
However, Unit 42 reports that the fake Python PoC script is actually a modification of a publicly available exploit for another flaw, CVE-2023-25157, a critical SQL injection flaw affecting GeoServer.
When executed, instead of executing the exploit, the PoC creates a batch script that downloads a coded PowerShell script and executes it on the target device.
The reported script downloads the VenomRAT malware and creates a scheduled task to run it every three minutes.
VenomRAT infections
Once VenomRAT is executed on a Windows device, it runs a key logger that records all keystrokes and saves them to a locally stored text file.
The malware then establishes communication with the C2 server, from where it receives one of the nine following commands to execute on the infected device:
- plu_gin: Activates a plugin that is stored in the registry.
- HVNCStop: Kills the “cvtres” process
- loadofflinelog: Sends offline key logger data from %APPDATA%.
- save_Plugin: Saves a plugin to the registry under a hardware ID.
- runningapp: Displays active processes.
- keylogsetting: Updates the key log file in the %APPDATA% folder.
- init_reg: Deletes the subkeys in the Software registry under a hardware identifier.
- Po_ng: Measures the time between a PING to the C2 server and the receipt of this command.
- filterinfo: Displays installed applications and active processes from the registry.
As the malware can be used to install other payloads and steal credentials, anyone who ran this fake PoC should change their passwords for all websites and environments they have an account on.
The timeline of events shared by Unit 42 indicates that the hacker prepared the infrastructure for the attack and payload before the public disclosure of the WinRAR vulnerability and then waited for the right moment to create a fake PoC.
This implies that the same attacker may, in the future, exploit the security community's increased attention to newly discovered vulnerabilities to spread other misleading PoCs for various flaws.
Information source: bleepingcomputer.com
