Google says government-backed hackers linked to Russia and China are exploiting a since-patched zero-day in WinRAR, first discovered in August 2023
Google security researchers say they have found evidence that government-backed hackers linked to Russia and China are exploiting …
Context & Ripple Effects
This report broadens a contemporaneous pattern of state-linked zero-day activity: Google had also described a separate North Korea-linked campaign targeting security researchers through an unfixed flaw in widely used software.
It also sits within a larger rise in observed exploitation. Google later counted 97 zero-days used in the wild during 2023, with espionage actors accounting for a substantial share.
First-order effects
- Organizations running unpatched WinRAR versions face an active risk from the reported Russia- and China-linked exploitation, making deployment of the existing fix the immediate defensive priority.
- Google’s finding gives defenders attribution context for investigations involving malicious WinRAR archives and helps focus threat hunting on activity associated with the reported campaigns.
Second-order effects
- The episode puts more pressure on enterprises to maintain software inventories and shorten patching cycles for ubiquitous desktop utilities, not only operating systems and browsers.
- Security vendors and incident-response teams are likely to prioritize detection coverage for exploit attempts against WinRAR, because a public patch does not remove exposure from systems that have not updated.
Third-order effects
- If state-backed groups continue to exploit common third-party applications, endpoint security will depend increasingly on rapid patch adoption across the full software stack rather than perimeter controls alone.
- The case reinforces a durable zero-day market dynamic: vulnerabilities in broadly deployed software can serve multiple state-linked actors, raising the value of coordinated disclosure, telemetry, and exploit detection.
The trend: State-linked operators are increasingly treating unpatched vulnerabilities in widely deployed software as reusable access paths, intensifying the operational importance of patch speed.