A utility as old and popular as WinRAR, as it was revealed last month, has been vulnerable for the last 19 years to an error that can be easily exploited by hackers and malware distributors. Fortunately, the software has been patched in the recent version 5.70. However, many users have not updated the program for a long time and do this rarely, so now a new wave of malware is actively taking advantage of the issue.

Security researchers at Check Point, who discovered the vulnerability, explained that the error in the archiver is exploited by distributing malicious archives with the RAR extension, so that when opened, they can automatically extract malicious code. These programs are installed in the PC's startup folder and run anytime the computer is on, all without the user's knowledge.

Once the flaw was disclosed, hacker groups began to exploit it for their own interests, and various countries became targets of cyber espionage campaigns attempting to gather intelligence. Security software firm McAfee noted that more than 100 unique exploits utilizing the WinRAR error have already been discovered, most of which are aimed at the United States.
Malware distributors are well aware of WinRAR's popularity among those who prefer to illegally download various media files. McAfee notes that one of the most popular exploits targets those searching online for pirate copies of Ariana Grande's latest album — Thank U, Next.
WinRAR exploit (#CVE-2018-20250) sample (united nations .rar) seems to be targeting the Middle East. Embedded with bait documents relating to the United Nations Human Rights and the #UN in Arabic, it finally downloads and executes #Revenge RAT. https://t.co/WJ4oJ1UxAz pic.twitter.com/fgHYSD4Mk5
— 360 Threat Intelligence Center (@360TIC) March 12, 2019.
While the WinRAR utility is not as popular today as it was many years ago, with nearly 500 million users over almost 20 years, it's hard to say how many systems remain vulnerable to this attack. Additionally, even though version 5.70 was released at the end of January, it needs to be manually downloaded and installed from the official website, meaning that most users are unaware of this critical update.
Source: 3dnews.ru
