/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

ESET says two Russian cybercrime groups are exploiting a high-severity WinRAR zero-day, backdooring computers that open malicious archives in phishing messages

A high-severity zero-day in the widely used WinRAR file compressor is under active exploitation by two Russian cybercrime groups.

Ars Technica Dan Goodin

Context & Ripple Effects

WinRAR has repeatedly been an exploitation target: researchers documented more than 100 distinct exploits of an earlier code-execution flaw in 2019, and a later WinRAR zero-day was exploited by Russia- and China-linked government-backed actors in 2023. The recurrence makes archive handling a persistent endpoint-security exposure rather than a one-off vulnerability class.

This report shifts the immediate focus to criminal operators using phishing-delivered archives. It also follows WinRAR's 2023 fix for a flaw that could enable arbitrary code execution, underscoring that attackers continue to seek leverage from a widely used file format and application.

First-order effects

  • Recipients who open the malicious phishing archives risk having their computers backdoored by the two identified groups.
  • Defenders must prioritize investigation of suspicious WinRAR archives and the endpoints that opened them, since exploitation is reported as active rather than merely theoretical.

Second-order effects

  • Email-security and endpoint teams face pressure to improve inspection, blocking, and incident response for archive-based lures, a delivery path with a documented history of diverse exploit use in earlier WinRAR code-execution campaigns.
  • Organizations that rely on WinRAR in user workflows may need to reassess how archives from external senders are handled, including whether they reach endpoints at all.

Third-order effects

  • If repeated exploitation persists, archive utilities will remain high-value initial-access targets despite their mundane role in business workflows, raising the security cost of broadly distributed desktop software.
  • The pattern favors layered controls around file delivery and execution over reliance on a single patch or phishing filter; the report does not establish whether this specific flaw has a fix available.

The trend: This is another data point in the durable shift toward exploiting trusted, widely installed desktop utilities as an entry point for targeted phishing operations.

Discussion

  • @campuscodi@mastodon.social Catalin Cimpanu on mastodon
    @campuscodi@mastodon.social boosted the following from https://infosec.exchange/@ESETresearch/ 115009326852771403  —  #ESETresearch has discovered a zero-day vulnerability in WinRAR, exploited in the wild by Russia-aligned #RomCom  —  https://www.welivesecurity.com/ ... …
  • r/pcmasterrace r on reddit
    Newly discovered WinRAR exploit linked to Russian hacking group, can plant backdoor malware — zero day hack requires manual update to fix
  • r/cybersecurity r on reddit
    Update WinRAR tools now: RomCom and others exploiting zero-day vulnerability
  • r/technews r on reddit
    Newly discovered WinRAR exploit linked to Russian hacking group, can plant backdoor malware — zero day hack requires manual update to fix
  • r/europe r on reddit
    Newly discovered WinRAR exploit linked to Russian hacking group, can plant backdoor malware — zero day hack requires manual update to fix | …
  • r/hacking r on reddit
    WinRAR zero-day exploited to plant malware on archive extraction
  • r/technology r on reddit
    Newly discovered WinRAR exploit linked to Russian hacking group, can plant backdoor malware — zero day hack requires manual update to fix