According to Google, various state-backed hacking groups have engaged in ongoing attacks, exploiting a vulnerability in WinRAR, a compression software used by over 500 million users, with the aim of gaining arbitrary code execution on targets' systems.
See also: Fake WinRAR proof-of-concept exploit drops VenomRAT malware

Google's Threat Analysis Group (TAG), a set of security experts who protect Google users from state-sponsored attacks, has identified state-sponsored hackers from several countries targeting the flaw , including the Sandworm , APT28, and APT40 threat groups from Russia and China.
In an attack in early September, Russian hackers from Sandworm distributed the Rhadamanthys infostealer malware through fake invitation attacks for a Ukrainian drone training school.
Another Russian hacker group, known as ATP28, attacked users in Ukraine by exploiting CVE-2023-38831 hosted on servers provided by a free hosting provider. During this attack, the malicious actors used a malicious PowerShell script (IRONJAW) to steal browser credentials.
Additionally, Chinese hackers from APT40 are exploiting a WinRAR vulnerability in attacks against targets in Papua New Guinea. They used ISLANDSTAGER and BOXRAT to maintain persistence on compromised systems
The CVE-2023-38831 WinRAR vulnerability has been actively exploited as a zero-day since at least April 2023, allowing threat actors to execute code on their victims' systems by tricking them into opening maliciously crafted RAR and ZIP archives containing decoy files.
See also: Hackers exploit a WinRAR zero-day bug to target crypto investors
Since April, the bug has been used to deliver a wide range of malware repositories, including DarkMe, GuLoader, and Remcos RATs.

Researchers at Group-IB have discovered exploits targeting cryptocurrency and stock market forums. Within hours of Group-IB publishing its findings, proof-of-concept exploits began appearing in public GitHub, leading directly to what the Google TAG team describes as “testing activity” of CVE-2023-38831 by financially motivated hacker groups and APTs.
Other cybersecurity companies have also linked attacks exploiting this WinRAR to various other threat groups, including DarkPink (NSFOCUS) and Konni (Knownsec).
The zero-day was patched with the release of WinRAR 6.23 on August 2, which also addressed several other security issues. One of them is CVE-2023-40477, a bug that can be exploited to enable command execution via specially crafted RAR files.
See also: Sandworm: Used WinRAR to destroy data of a Ukrainian government agency
Hackers using this exploit can carry out attacks with a high degree of severity. They can execute malicious software on the computer , bypassing security systems and protections that have been implemented. This leads not only to personal privacy violations, but also to significant attacks on network security.
The misuse of WinRAR creates a multitude of problems, which are of concern to both individual users and the wider IT community. These problems include:
- Breach of user data security
- Running malware without user knowledge
- Intrusion into corporate networks and violation of their security protocols
Therefore, it is absolutely critical to inform users about the risks involved in using WinRAR and the need to upgrade available versions of the software to more secure versions.
Source: bleepingcomputer
