HomeRapidalertURGENT: Compressed files are used for data theft attacks! Difficult to detect!

URGENT: Compressed files are used for data theft attacks! Difficult to detect!

Not even a week has passed since the publication of the vulnerability in Word files, which was detected by security researchers to be used to install remote management software in companies/organizations, and another vulnerability has made its appearance this time. The vulnerability, according to information available to SecNews, is in the Winrar application, which is widely used by a large number of users to decompress compressed RAR files (but also other extensions such as ZIP).

How the attack is carried out

The victim of a compressed file attack receives an attached file (with or without a password) where the sender (usually someone known to the victim with a compromised email address) tells them that they are attaching the sales file, the company's bonus list, compressed photos from the last event/party they attended together, or a work progress report form. The file is again compressed with a ZIP extension and a descriptive title (e.g. Action.Report.Week28.zip).

Once the user double-clicks on the compressed attachment, they see the supposedly compressed files which are word files or photos or audio files. Once they click on any file, it opens normally (whether it is a photo, audio file or word file) while at the same time and without the user noticing, the remote management software.

Therefore, would-be eavesdroppers/industrial spies, using the weakness in the Winrar application, manage to disorient their victims, altering file extensions to appear as photos, text files or audio files when in reality they are executable files!

Technical Details of the Attack

But how can this be done? Check out the methodology used by hackers (reposted from the blog of Ani7 hacker-security researcher) to create the supposed compressed files. The process is extremely simple and can be carried out by anyone with minimal knowledge!

When we compress a file in ZIP format with the WinRar application, the resulting file has the same structure, with the difference that Winrar adds some extra fields. For example, a file TEST1.txt containing the data “AAAAAA” after being compressed as a ZIP file (Test1.zip) with the application has the following format:

In our example, we notice that the Winrar application added the file name field to the compressed file. Additional analysis shows that the second name is the “File name” of the file, the name that the Winrar application will give to the extracted uncompressed file. The First name indicates the name of the file as displayed in the Winrar graphical environment (GUI). And that is exactly where the application’s weakness lies. What will happen if a malicious user alters the first and second names (i.e. the exported and the one shown in the application’s graphical environment)? So see what exactly they do!

Step 1

They first create the malicious application (which allows remote access to the victim's computer). In our example, a simple executable file has been used, which for demonstration purposes displays a simple window (PWNED)

Step 2

Compress the EXECUTABLE file with Winrar by selecting the WinZip method

Step 3 

They open the compressed file with a simple hex editor and change the second name ONLY to the fake desired name (e.g. MyPrivateImage.jpg) and select “Save” on the altered compressed file

Step 4

The result is that when the unsuspecting victim opens the compressed file with the Winrar application, the executable file will be automatically executed while the user will see a compressed photo (and not an executable file)

Required actions

SecNews has at its disposal a relevant file from an attack carried out against a public utility organization, sent by a friend of the website's administrator. After research we conducted, we found that this particular attack methodology has been on the rise in recent weeks, in particular in combination with the attack with Word files that we published a few days ago.  

According to the data obtained, the SecNews technical team recommends :

a) Administrators of public services, organizations and companies must immediately carry out a sample check on incoming compressed files! In addition, with the above notification, we estimate that the entry of compressed files from unknown senders to employee e-mails should be prevented.

b) The attack and the malware installation, according to the same information, are not detected by any known Antivirus/Antimalware while bypassing almost any Proxy server/content filter that provides Internet access to the terminal computer.

c) Administrators of public services, organizations, financial institutions and companies must inform users with relevant announcements about the possible download of strange zip files with attached photos, audio files or word documents. As a protection measure, it would probably be right to disallow the use of zip files for a limited period of time, by adding filters at the Antispam or Mailserver level.

d) IMMEDIATELY uninstall the Winrar application where it is installed on user terminals (especially in IT addresses).

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS