Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Cybercrime

Recently Patched WinRAR Flaw Exploited in APT Attacks

A recently patched WinRAR vulnerability has been exploited by several threat groups, including advanced persistent threat (APT) actors.

A recently patched WinRAR vulnerability has been exploited by several threat groups, including advanced persistent threat (APT) actors.

The flaw, tracked as CVE-2018-20250, impacts the unacev2.dll library used by WinRAR for unpacking ACE archives. Starting with WinRAR 5.70, the problematic library has been removed to prevent abuse, but many users have failed to update the application, allowing malicious actors to continue launching attacks.

The WinRAR security hole can be exploited via specially crafted ACE archives to extract a harmless file to the destination folder selected by the user, while also extracting a malicious file to a location specified by the attacker. An attacker can achieve arbitrary code execution by extracting a piece of malware to the Windows Startup folder, ensuring that it would get executed the next time the operating system boots.

Technical details of the vulnerability, which is believed to have existed for 19 years, were made public by Check Point Software Technologies on February 20. The first attacks exploiting the vulnerability to deliver a piece of malware were spotted a few days later.

In a blog post published on Thursday, McAfee said it had spotted over 100 unique exploits targeting the vulnerability in the first week after the flaw was disclosed. The company said most of the initial targets resided in the United States.

In one of the attacks observed by McAfee, hackers delivered an ACE file that appeared to contain a bootlegged copy of Ariana Grande’s “thank u, next” album. If the user attempts to extract the content of the archive, some MP3 files are extracted, but a piece of malware is also silently planted in the Startup folder.

Advertisement. Scroll to continue reading.

The 360 Threat Intelligence Center of Chinese cybersecurity firm Qihoo 360 has also spotted several attacks, including ones that appear to have been launched by APT actors. Its researchers have seen attacks aimed at Ukraine, the Middle East (Revenge RAT delivered with bait documents referencing the United Nations), and others.

South Korean security firm ESTsecurity says it has seen APT attacks aimed at South Korean users in which hackers attempted to deliver malware with documents referencing the recent Hanoi Summit between North Korean Chairman Kim Jong-un and U.S. President Donald Trump.

Related: Microsoft Patches Two Windows Flaws Exploited in Targeted Attacks

Related: Malicious PDF Leads to Discovery of Adobe Reader, Windows Zero-Days

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs.

Register

In this live webinar, learn how to define your minimum viable business, identify the systems it depends on, measure actual recovery time against business requirements, and present the gaps to the board as measurable risk.

Register

People on the Move

Social engineering protection company Doppel has promoted Alyssa Smrekar to Chief Marketing Officer.

Naveen Bhateja has been appointed Chief People Officer at HackerOne.

The Department of War has appointed Sonu Shankar as Principal Deputy Chief Information Officer.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.