Patch WinRAR now - it's got a major security flaw

Illustration of a laptop with a magnifying glass exposing a beetle on-screen
(Image credit: Shutterstock / Kanoktuch)

Russian and Chinese state-sponsored threat actors have been discovered abusing a known vulnerability in the popular archiving tool WinRAR to extract sensitive information such as passwords and other login credentials.

Google’s Threat Analysis Group (TAG), which usually tracks and analyzes state-sponsored hacking players, claims to have found evidence that the flaw, identified earlier as CVE-2023-38831 by Group-IB, was being used to hide malware in archived files. 

To the average Joe, the files would look like your average image, or text document. However, when downloaded and extracted, they’d infect the device with infostealing malware, capable of grabbing different files and information from the endpoint, such as passwords and payment data stored in browsers, various system information, and more.

Sandworm, APT40, and others

To make matters worse, this isn’t just one or two groups targeting WinRAR users - apparently, it’s “multiple” groups targeting “many users” who are yet to apply the patch. 

The patch does exist, however, RarLab, the company behind WinRAR, released version 6.23 in early August this year, to address the issue. However, there is no way to update the program from within. Users need to head over to the WinRAR website, download the latest version, and run the installer as if they’re installing the program from scratch.

Users will want to patch, though, as one of the groups was identified as Sandworm, a Russian military intelligence unit that allegedly interfered with the 2016 presidential elections in the United States. It was also observed as quite an active player in the Russia-Ukraine war, and was behind the infamous 2017 NotPetya ransomware attack.

Another identified player is APT40, a Chinese hacking collective allegedly tied to the Chinese Ministry of State Security. It used the flaw to target endpoints in Papua New Guinea via a Dropbox link. 

The WinRar vulnerability “highlights that exploits for known vulnerabilities can be highly effective”, TAG’s researchers concluded.

Via TechCrunch

More from TechRadar Pro

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
A computer being guarded by cybersecurity.
Worrying Windows security issue patched by 7-Zip, so patch now
Avast cybersecurity
An unpatched Windows zero-day flaw has been exploited by 11 nation-state attackers
A digital representation of a lock
Security experts are being targeted with fake malware discoveries
email
A Windows filetype update may have complicated cyber threat detection efforts
Representational image of a cybercriminal
Microsoft discovers five potentially damaging attacks against its own software
A group of 7 hackers, 6 slightly blurred in the background and one in the foreground, all wearing black with hoods pulled up over their heads. You cannot see their faces. The hacker in the foreground sits with an open laptop in front of them. The background, behind the hackers, is a Chinese flag
China government-linked hackers caught running a seriously dangerous ransomware scam
Latest in Security
UK Prime Minister Sir Kier Starmer
The UK releases timeline for migration to post-quantum cryptography
ransomware avast
Ransomware attacks are costing Government offices a month of downtime on average
Lock on Laptop Screen
Data breach at Pennsylvania education union potentially exposes 500,000 victims
Data leak
Top collectibles site leaks personal data of nearly a million users
Spyware
Stalkerware data breach potentially hits over 2 million users, including thousands of Apple devices
An American flag flying outside the US Capitol building against a blue sky
Five Eyes "cannot replace US intel in Ukraine", claims former US Cyber Command Chief
Latest in News
Using Zipped files and folders in Windows 11
Windows 11 should soon be faster at extracting files from compressed ZIPs – and it’s about time, frankly
The player prepares for a fight in Metal Eden.
I loved the bits of Metal Eden that I played and soon you'll be able to try it too thanks to this upcoming free demo
Apple iPhone 16 Pro HANDS ON
The iPhone 18 might get a major chip upgrade after all
UK Prime Minister Sir Kier Starmer
The UK releases timeline for migration to post-quantum cryptography
Oppo Watch Mini X2 teaser
Oppo Watch X2 Mini teaser could be our first glimpse of the smaller OnePlus Watch 3
The Samsung Galaxy S25 Edge on display the January 22, 2025 Galaxy Unpacked event.
A fresh Samsung Galaxy S25 Edge benchmark leak has eased my worries about its performance