Although Windows 11 may want to reduce its influence with native support for the 7Z, RAR, TAR and GZ formats, WinRAR is still one of the most commonly used compression applications today. However, for those who usually use WinRAR, here is a reminder to update the software as soon as possible, because it is reported that some state-sponsored bad actors are exploiting its security holes to breach users’ digital security.

WinRAR has major security vulnerabilities, please update manually immediately!
exist A blog post published by Google, the company said its Threat Analysis Group (TAG) has identified multiple instances of hacker groups exploiting now-patched vulnerabilities in WinRAR. Apparently, the compression software has a security vulnerability that causes Windows ShellExecute behavior when trying to open files with spaces in their file extensions, allowing attackers to execute arbitrary code when users try to view benign files (such as ordinary PNG files) in ZIP files.

Although this security flaw has been Patched by WinRAR developer RARLabs in August 2023, but several hacker groups, including FROZENBARENTS, FROZENLAKE, and ISLANDDREAMS, have been exploiting issues in unpatched software to carry out malicious activities in countries including Ukraine and Papua New Guinea. Here is an actual case. A hacker group affiliated with the General Staff of the Russian Armed Forces (GRU) sent an email posing as a Ukrainian drone warfare training school. It included a link to the anonymous file sharing service fex, which provided a harmless decoy PDF file containing a drone operator training course and a malicious ZIP file that exploited vulnerabilities.

The key reason why it is widely exploited is that WinRAR itself does not update automatically, which means users running older versions of the software are easily exploited. As of now, WinRAR versions 6.23 and 6.24 contain security fixes. If you are a WinRAR user, pleaseBe sure to download the latest version from the official websiteUpdate fix.

Google pointed out that the spread of this vulnerability not only emphasizes the importance of users keeping their software up to date, but also emphasizes the obligation of vendors to provide easier methods of software updates to protect users from infringement. If you are curious about how this vulnerability is exploited, or want to know the related Indicators of Compromise (IOC), be sure to read This blog post from Google。
Source: KOCPC Chinese