https://www.bleepingcomputer.com/news/security/winrar-zero-day-exploited-since-april-to-hack-trading-accounts/ BleepingComputer.com logo * * * * [ ] [Login] [Sign up] * * * * [ ] [Login] [Sign up] * News + Featured + Latest + WinRAR zero-day exploited since April to hack trading accounts WinRAR zero-day exploited since April to hack trading accounts + New HiatusRAT malware attacks target US Defense Department New HiatusRAT malware attacks target US Defense Department + Microsoft Excel to let you run Python scripts as formulas Microsoft Excel to let you run Python scripts as formulas + Akira ransomware targets Cisco VPNs to breach organizations Akira ransomware targets Cisco VPNs to breach organizations + Lapsus$ teen hackers convicted of high-profile cyberattacks Lapsus$ teen hackers convicted of high-profile cyberattacks + Windows 10 KB5029331 update introduces a new Backup app Windows 10 KB5029331 update introduces a new Backup app + Over 3,000 Openfire servers vulnerable to takover attacks Over 3,000 Openfire servers vulnerable to takover attacks + Bitwarden releases free and open-source E2EE Secrets Manager Bitwarden releases free and open-source E2EE Secrets Manager * Downloads + Latest + Most Downloaded + Qualys BrowserCheck Qualys BrowserCheck + STOPDecrypter STOPDecrypter + AuroraDecrypter AuroraDecrypter + FilesLockerDecrypter FilesLockerDecrypter + AdwCleaner AdwCleaner + ComboFix ComboFix + RKill RKill + Junkware Removal Tool Junkware Removal Tool * VPNs + Popular + Best VPNs Best VPNs + How to change IP address How to change IP address + Access the dark web safely Access the dark web safely + Best VPN for YouTube Best VPN for YouTube * Virus Removal Guides + Latest + Most Viewed + Ransomware + Remove the Theonlinesearch.com Search Redirect Remove the Theonlinesearch.com Search Redirect + Remove the Smartwebfinder.com Search Redirect Remove the Smartwebfinder.com Search Redirect + How to remove the PBlock+ adware browser extension How to remove the PBlock+ adware browser extension + Remove the Toksearches.xyz Search Redirect Remove the Toksearches.xyz Search Redirect + Remove Security Tool and SecurityTool (Uninstall Guide) Remove Security Tool and SecurityTool (Uninstall Guide) + How to Remove WinFixer / Virtumonde / Msevents / Trojan.vundo How to Remove WinFixer / Virtumonde / Msevents / Trojan.vundo + How to remove Antivirus 2009 (Uninstall Instructions) How to remove Antivirus 2009 (Uninstall Instructions) + How to remove Google Redirects or the TDSS, TDL3, or Alureon rootkit using TDSSKiller How to remove Google Redirects or the TDSS, TDL3, or Alureon rootkit using TDSSKiller + Locky Ransomware Information, Help Guide, and FAQ Locky Ransomware Information, Help Guide, and FAQ + CryptoLocker Ransomware Information Guide and FAQ CryptoLocker Ransomware Information Guide and FAQ + CryptorBit and HowDecrypt Information Guide and FAQ CryptorBit and HowDecrypt Information Guide and FAQ + CryptoDefense and How_Decrypt Ransomware Information Guide and FAQ CryptoDefense and How_Decrypt Ransomware Information Guide and FAQ * Tutorials + Latest + Popular + How to enable Kernel-mode Hardware-enforced Stack Protection in Windows 11 How to enable Kernel-mode Hardware-enforced Stack Protection in Windows 11 + How to use the Windows Registry Editor How to use the Windows Registry Editor + How to backup and restore the Windows Registry How to backup and restore the Windows Registry + How to open a Windows 11 Command Prompt as Administrator How to open a Windows 11 Command Prompt as Administrator + How to start Windows in Safe Mode How to start Windows in Safe Mode + How to remove a Trojan, Virus, Worm, or other Malware How to remove a Trojan, Virus, Worm, or other Malware + How to show hidden files in Windows 7 How to show hidden files in Windows 7 + How to see hidden files in Windows How to see hidden files in Windows * Deals + Categories + eLearning eLearning + IT Certification Courses IT Certification Courses + Gear & Gadgets Gear + Gadgets + Security Security * Forums * More + Startup Database + Uninstall Database + Glossary + Chat on Discord + Send us a Tip! + Welcome Guide * Home * News * Security * WinRAR zero-day exploited since April to hack trading accounts * * WinRAR zero-day exploited since April to hack trading accounts By Bill Toulas * August 23, 2023 * 09:53 AM * 0 ZIP A WinRar zero-day vulnerability tracked as CVE-2023-38831 was actively exploited to install malware when clicking on harmless files in an archive, allowing the hackers to breach online cryptocurrency trading accounts. The vulnerability has been under active exploitation since April 2023, helping distribute various malware families, including DarkMe, GuLoader, and Remcos RAT. The WinRAR zero-day vulnerability allowed the threat actors to create malicious .RAR and .ZIP archives that displayed seemingly innocuous files, such as JPG (.jpg) images, text files (.txt), or PDF (.pdf) documents. However, when a user opens the document, the flaw will cause a script to be executed that installs malware on the device. BleepingComputer tested a malicious archive shared by Group-IB, who discovered the campaign, and simply double-clicking on a PDF caused a CMD script to be executed to install malware. The zero-day was fixed in WinRAR version 6.23, released on August 2, 2023, which also resolves several other security issues, including CVE-2023-40477, a flaw that can trigger command execution upon opening a specially crafted RAR file. Targeting crypto traders In a report released today, researchers from Group-IB said they discovered the WinRAR zero-day being used to target cryptocurrency and stock trading forums, where the hackers pretended to be other enthusiasts sharing their trading strategies. These forum posts contained links to specially crafted WinRAR ZIP or RAR archives that pretended to include the shared trading strategy, consisting of PDFs, text files, and images. Promoting malicious archives on a crypto trader forumPromoting malicious archives on a crypto trader forum Source: Group-IB The fact that those archives target traders is demonstrated by the forum post titles, like "best Personal Strategy to trade with Bitcoin." The malicious archives were distributed on at least eight public trading forums, infecting a confirmed 130 traders' devices. The number of victims and financial losses resulting from this campaign are unknown. When the archives are opened, users will see what appears to be a harmless file, like a PDF, with a folder matching the same file name, as shown below. Contents of a malicious ZIP archiveContents of a malicious ZIP archive Source: BleepingComputer However, when the user double-clicks on the PDF, the CVE-2023-38831 vulnerability will quietly launch a script in the folder to install malware on the device. At the same time, these scripts will also load the decoy document so as not to arouse suspicion. Windows CMD script executed by CVE-2023-38831 vulnerabilityWindows CMD script executed by CVE-2023-38831 vulnerability Source: BleepingComputer The vulnerability is triggered by creating specially crafted archives with a slightly modified structure compared to safe files, which causes WinRAR's ShellExecute function to receive an incorrect parameter when it attempts to open the decoy file. This results in the program skipping the harmless file and instead locating and executing a batch or CMD script, so while the user assumes they open a safe file, the program launches a different one. The script executes to launch a self-extracting (SFX) CAB archive that infects the computer with various malware strains, such as the DarkMe, GuLoader, and Remcos RAT infections, providing remote access to an infected device. Although the DarkMe malware strain has been associated with the financially motivated EvilNum group, it is unclear who leveraged CVE-2023-38831 in the recently observed campaign. Infection chain leveraging CVE-2023-38831Infection chain leveraging CVE-2023-38831 Source: Group-IB DarkMe has been previously used in financially motivated attacks, so it's possible that the attackers target traders to steal their crypto assets. Remcos RAT gives the attackers more powerful control over infected devices, including arbitrary command execution, keylogging, screen capturing, file management, and reverse proxy capabilities, so it could facilitate espionage operations too. Group-IB discovered CVE-2023-38831 in July 2023, and the security firm has today published a detailed report on its in-the-wild exploitation. Users of WinRAR are urged to upgrade to the latest version, version 6.23 at the time of this writing, as soon as possible to eliminate the risk of file spoofing and other recently-disclosed attacks. Related Articles: WinRAR flaw lets hackers run programs when you open RAR archives Norwegian government IT systems hacked using zero-day flaw Adobe fixes patch bypass for exploited ColdFusion CVE-2023-29298 flaw Microsoft July 2023 Patch Tuesday warns of 6 zero-days, 132 flaws Over 3,000 Openfire servers vulnerable to takover attacks * Actively Exploited * Archive * Malware * Software * Vulnerability * WinRAR * Zero-Day * Zip * * * * * Bill Toulas Bill Toulas is a tech writer and infosec news reporter with over a decade of experience working on various online publications, covering open-source, Linux, malware, data breach incidents, and hacks. * Previous Article * Next Article Post a Comment Community Rules You need to login in order to post a comment [Login] Not a member yet? Register Now You may also like: [INS::INS] [mwise-join-forces] Popular Stories * Duolingo Scraped data of 2.6 million Duolingo users released on hacking forum * Duo Ongoing Duo outage causes Azure Auth authentication errors Follow us: * * * * * Main Sections * News * VPN Buyer Guides * Downloads * Virus Removal Guides * Tutorials * Startup Database * Uninstall Database * Glossary Community * Forums * Forum Rules * Chat Useful Resources * Welcome Guide * Sitemap Company * About BleepingComputer * Contact Us * Send us a Tip! * Advertising * Write for BleepingComputer * Social & Feeds * Changelog Terms of Use - Privacy Policy - Ethics Statement - Affiliate Disclosure Copyright @ 2003 - 2023 Bleeping Computer^(r) LLC - All Rights Reserved Login Username [ ] Password [ ] [*] Remember Me [ ] Sign in anonymously [Login] Sign in with Twitter button Sign in with Twitter --------------------------------------------------------------------- Not a member yet? Register Now Reporter Help us understand the problem. What is going on with this comment? * ( )Spam * ( )Abusive or Harmful * ( )Inappropriate content * ( )Strong language * ( )Other [ ] * [ ] Read our posting guidelinese to learn what content is prohibited. Submitting... SUBMIT