Close Menu
GeekBlog

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    These $500 Windows Laptops Show the MacBook Neo’s Competition

    March 5, 2026

    TerraPower gets OK to start construction of its first nuclear plant

    March 5, 2026

    Jensen Huang says Nvidia is pulling back from OpenAI and Anthropic, but his explanation raises more questions than it answers

    March 5, 2026
    Facebook X (Twitter) Instagram Threads
    GeekBlog
    • Home
    • Mobile
    • Tech News
    • Blog
    • How-To Guides
    • AI & Software
    Facebook
    GeekBlog
    Home»Tech News»High-severity WinRAR 0-day exploited for weeks by 2 groups
    Tech News

    High-severity WinRAR 0-day exploited for weeks by 2 groups

    Michael ComaousBy Michael ComaousAugust 12, 20253 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
    High-severity WinRAR 0-day exploited for weeks by 2 groups
    Share
    Facebook Twitter LinkedIn Pinterest Email Copy Link

    BI.ZONE said the Paper Werewolf delivered the exploits in July and August through archives attached to emails impersonating employees of the All-Russian Research Institute. The ultimate goal was to install malware that gave Paper Werewolf access to infected systems.

    While the discoveries by ESET and BI.ZONE were independent of each other, it’s unknown if the groups exploiting the vulnerabilities are connected or acquired the knowledge from the same source. BI.ZONE speculated that Paper Werewolf may have procured the vulnerabilities in a dark market crime forum.

    ESET said the attacks it observed followed three execution chains. One chain, used in attacks targeting a specific organization, executed a malicious DLL file hidden in an archive using a method known as COM hijacking that caused it to be executed by certain apps such as Microsoft Edge. It looked like this:

    Illustration of the execution chain installing Mythic Agent.

    Credit:
    ESET

    Illustration of the execution chain installing Mythic Agent.


    Credit:

    ESET

    The DLL file in the archive decrypted embedded shellcode, which went on to retrieve the domain name for the current machine and compare it with a hardcoded value. When the two matched, the shellcode installed a custom instance of the Mythic Agent exploitation framework.

    A second chain ran a malicious Windows executable to deliver a final payload installing SnipBot, a known piece of RomCom malware. It blocked some attempts at being forensically analyzed by terminating when opened in an empty virtual machine or sandbox, a practice common among researchers. A third chain made use of two other known pieces of RomCom malware, one known as RustyClaw and the other Melting Claw.

    WinRAR vulnerabilities have previously been exploited to install malware. One code-execution vulnerability from 2019 came under wide exploitation in 2019 shortly after being patched. In 2023, a WinRAR zero-day was exploited for more than four months before the attacks were detected.

    Besides its massive user base, WinRAR makes a perfect vehicle for spreading malware because the utility has no automated mechanism for installing new updates. That means users must actively download and install patches on their own. What’s more, ESET said Windows versions of the command line utilities UnRAR.dll and the portable UnRAR source code are also vulnerable. People should steer clear of all WinRAR versions prior to 7.13, which, at the time this post went live, was the most current. It has fixes for all known vulnerabilities, although given the seemingly unending stream of WinRAR zero-days, it isn’t much of an assurance.

    0day exploited groups Highseverity weeks WinRAR
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email Copy Link
    Previous ArticleIntel’s CEO has successfully wooed President Trump
    Next Article Newegg Promo Code: 10% Off August 2025
    Michael Comaous
    • Website

    Michael Comaous is a dedicated professional with a passion for technology, innovation, and creative problem-solving. Over the years, he has built experience across multiple industries, combining strategic thinking with hands-on expertise to deliver meaningful results. Michael is known for his curiosity, attention to detail, and ability to explain complex topics in a clear and approachable way. Whether he’s working on new projects, writing, or collaborating with others, he brings energy and a forward-thinking mindset to everything he does.

    Related Posts

    3 Mins Read

    These $500 Windows Laptops Show the MacBook Neo’s Competition

    2 Mins Read

    TerraPower gets OK to start construction of its first nuclear plant

    3 Mins Read

    Jensen Huang says Nvidia is pulling back from OpenAI and Anthropic, but his explanation raises more questions than it answers

    1 Min Read

    A new video from the White House mixes Call of Duty footage with actual video of Iran strikes

    6 Mins Read

    I was planning to get the Galaxy S26 Ultra, but these downgrades made me rethink

    2 Mins Read

    The New United Airlines Policy That Could Get You Kicked Off a Flight

    Top Posts

    Discord will require a face scan or ID for full access next month

    February 9, 2026761 Views

    The Mesh Router Placement Strategy That Finally Gave Me Full Home Coverage

    August 4, 2025565 Views

    Past Wordle answers – all solutions so far, alphabetical and by date

    August 1, 2025230 Views
    Stay In Touch
    • Facebook

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    Discord will require a face scan or ID for full access next month

    February 9, 2026761 Views

    The Mesh Router Placement Strategy That Finally Gave Me Full Home Coverage

    August 4, 2025565 Views

    Past Wordle answers – all solutions so far, alphabetical and by date

    August 1, 2025230 Views
    Our Picks

    These $500 Windows Laptops Show the MacBook Neo’s Competition

    March 5, 2026

    TerraPower gets OK to start construction of its first nuclear plant

    March 5, 2026

    Jensen Huang says Nvidia is pulling back from OpenAI and Anthropic, but his explanation raises more questions than it answers

    March 5, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook
    • About Us
    • Contact us
    • Privacy Policy
    • Disclaimer
    • Terms and Conditions
    © 2026 GeekBlog

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.