Close Menu
    Facebook LinkedIn YouTube WhatsApp X (Twitter) Pinterest
    Trending
    • Alcovia Ford Nugget-style six-sleeper Ducato camper van
    • AI is already across your business and its carbon impact probably is too
    • Good Luck Getting a Mac Mini for the Next ‘Several Months’
    • The most severe Linux threat to surface in years catches the world flat-footed
    • Apple Plugs Security Hole That Enabled FBI to Access Deleted Signal Messages on iPhone
    • GPU Performance Comparison Shows Surprising Variability
    • How to Study the Monotonicity and Stability of Variables in a Scoring Model using Python
    • Vision-only manipulation is hitting a wall
    Facebook LinkedIn WhatsApp
    Times FeaturedTimes Featured
    Friday, May 1
    • Home
    • Founders
    • Startups
    • Technology
    • Profiles
    • Entrepreneurs
    • Leaders
    • Students
    • VC Funds
    • More
      • AI
      • Robotics
      • Industries
      • Global
    Times FeaturedTimes Featured
    Home»News»High-severity WinRAR 0-day exploited for weeks by 2 groups
    News

    High-severity WinRAR 0-day exploited for weeks by 2 groups

    Editor Times FeaturedBy Editor Times FeaturedAugust 18, 2025No Comments3 Mins Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr WhatsApp Email
    Share
    Facebook Twitter LinkedIn Pinterest Telegram Email WhatsApp Copy Link


    BI.ZONE stated the Paper Werewolf delivered the exploits in July and August via archives hooked up to emails impersonating workers of the All-Russian Analysis Institute. The last word purpose was to put in malware that gave Paper Werewolf entry to contaminated methods.

    Whereas the discoveries by ESET and BI.ZONE have been impartial of one another, it’s unknown if the teams exploiting the vulnerabilities are related or acquired the data from the identical supply. BI.ZONE speculated that Paper Werewolf could have procured the vulnerabilities in a darkish market crime discussion board.

    ESET stated the assaults it noticed adopted three execution chains. One chain, utilized in assaults concentrating on a particular group, executed a malicious DLL file hidden in an archive utilizing a technique generally known as COM hijacking that triggered it to be executed by sure apps corresponding to Microsoft Edge. It appeared like this:

    Illustration of the execution chain putting in Mythic Agent.

    Credit score:
    ESET

    Illustration of the execution chain putting in Mythic Agent.


    Credit score:

    ESET

    The DLL file within the archive decrypted embedded shellcode, which went on to retrieve the area identify for the present machine and examine it with a hardcoded worth. When the 2 matched, the shellcode put in a customized occasion of the Mythic Agent exploitation framework.

    A second chain ran a malicious Home windows executable to ship a remaining payload putting in SnipBot, a identified piece of RomCom malware. It blocked some makes an attempt at being forensically analyzed by terminating when opened in an empty digital machine or sandbox, a apply frequent amongst researchers. A 3rd chain made use of two different identified items of RomCom malware, one generally known as RustyClaw and the opposite as Melting Claw.

    WinRAR vulnerabilities have beforehand been exploited to put in malware. One code-execution vulnerability from 2019 got here under vast exploitation in 2019 shortly after being patched. In 2023, a WinRAR zero-day was exploited for greater than four months earlier than the assaults have been detected.

    In addition to its huge person base, WinRAR makes an ideal car for spreading malware as a result of the utility has no automated mechanism for putting in new updates. Which means customers should actively download and set up patches on their very own. What’s extra, ESET stated Home windows variations of the command-line utilities UnRAR.dll and the moveable UnRAR supply code are additionally susceptible. Folks ought to avoid all WinRAR variations previous to 7.13, which, on the time this put up went stay, was essentially the most present. It has fixes for all identified vulnerabilities, though given the seemingly never-ending stream of WinRAR zero-days, it isn’t a lot of an assurance.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Editor Times Featured
    • Website

    Related Posts

    The most severe Linux threat to surface in years catches the world flat-footed

    April 30, 2026

    Meta says it might be forced to withdraw its apps from New Mexico if a judge orders it to adopt the state’s proposed safety features (Thomas Barrabi/New York Post)

    April 30, 2026

    when asked whether xAI has ever distilled tech from OpenAI, Elon Musk says the claim is “partly” true (New York Times)

    April 30, 2026

    US officials are preparing a wide-ranging AI policy memo that outlines rules for national security agencies’ AI use, including avoiding single vendors (Bloomberg)

    April 30, 2026

    OpenAI says its models, starting with GPT-5.1, “increasingly mentioned goblins, gremlins, and other creatures”, leading to prompt instructions to mitigate it (OpenAI)

    April 30, 2026

    CFTC Sues Wisconsin in Escalating Fight Over Prediction Market Regulation

    April 30, 2026

    Comments are closed.

    Editors Picks

    Alcovia Ford Nugget-style six-sleeper Ducato camper van

    May 1, 2026

    AI is already across your business and its carbon impact probably is too

    May 1, 2026

    Good Luck Getting a Mac Mini for the Next ‘Several Months’

    April 30, 2026

    The most severe Linux threat to surface in years catches the world flat-footed

    April 30, 2026
    Categories
    • Founders
    • Startups
    • Technology
    • Profiles
    • Entrepreneurs
    • Leaders
    • Students
    • VC Funds
    About Us
    About Us

    Welcome to Times Featured, an AI-driven entrepreneurship growth engine that is transforming the future of work, bridging the digital divide and encouraging younger community inclusion in the 4th Industrial Revolution, and nurturing new market leaders.

    Empowering the growth of profiles, leaders, entrepreneurs businesses, and startups on international landscape.

    Asia-Middle East-Europe-North America-Australia-Africa

    Facebook LinkedIn WhatsApp
    Featured Picks

    Side Projects Ignite Engineering Passion

    November 8, 2025

    Can-Am unveils new electric ATVs and Maverick X rc

    August 18, 2025

    Florida Man Enters the Encryption Wars

    April 19, 2025
    Categories
    • Founders
    • Startups
    • Technology
    • Profiles
    • Entrepreneurs
    • Leaders
    • Students
    • VC Funds
    Copyright © 2024 Timesfeatured.com IP Limited. All Rights.
    • Privacy Policy
    • Disclaimer
    • Terms and Conditions
    • About us
    • Contact us

    Type above and press Enter to search. Press Esc to cancel.