A utility as old and popular as WinRAR was revealed last month to have been vulnerable to a bug for the past 19 years that could be easily exploited by hackers and malware distributors. Luckily, the software has been patched in the recent build 5.70. However, many users have not updated the program for a long time and generally do it rarely, so now a new wave of malware is actively exploiting the problem.

The Check Point security researchers who discovered the vulnerability explained that the bug in the archiver is exploited by distributing malicious archives with the RAR extension so that when opened, they can automatically extract the malicious code. These programs are installed in the PC's startup folder, and then run any time the computer is turned on, all without the user's knowledge.

Once the bug was discovered, hacker groups really started to take advantage of it, and various countries became the target of cyber-espionage campaigns trying to gather intelligence. Software security company McAfee noted that more than 100 unique exploits using the WinRAR bug have already been discovered - most of them targeting the United States.
Malware distributors are well aware of the popularity of WinRAR among those who prefer to illegally download various media files. McAfee notes that one of the most popular exploits targets those who search the web for pirated copies of Ariana Grande's latest album, Thank U, Next.
WinRAR exploit (#CVE-2018-20250) sample (united nations .rar) seems targeting the Middle East. Embedded with bait documents relating to the United Nations Human Rights and the #UN in Arabic, it finally downloads and executes #Revenge RAT.https://t.co/WJ4oJ1UxAz pic.twitter.com/fgHYSD4Mk5
— 360 Threat Intelligence Center (@360TIC) March 12, 2019
Of course, the WinRAR utility is far from being as popular today as it was many years ago, but since the number of its users has reached 20 million people in almost 500 years, it is impossible to say how many systems continue to be vulnerable to this attack. Also, although version 5.70 was released at the end of January, it must be manually downloaded and installed from the official website, leaving most users unaware of the critical update.
Source: 3dnews.ru
