WinRAR patches zero-day bug that targeted stock and crypto traders

Share This Post

According to cybersecurity firm Group-IB, weaponized ZIP file archives were being shared on crypto trading forums, with each one containing a nasty surprise.

The developers behind file compression software WinRAR have patched a zero-day vulnerability that allowed hackers to install malware onto unsuspecting victims’ computers, enabling them to hack into their crypto and stock trading accounts.

On Aug. 23, Singapore-based cybersecurity firm Group-IB reported a zero-day vulnerability in the processing of the ZIP file format by WinRAR.

The zero-day vulnerability tracked as CVE-2023-38831, was exploited for approximately four months, allowing hackers to install malware when a victim clicked on files in an archive. The malware would then allow hackers to breach online crypto and stock trading accounts, according to the report.

Using the exploit, the threat actors were able to create malicious RAR and ZIP archives that displayed seemingly innocent files such as JPG images or PDF text documents. These weaponized ZIP archives were then distributed on trading forums targeting crypto traders offering strategies such as “best Personal Strategy to trade with Bitcoin.”

Once extracted and executed, the malware allows threat actors to withdraw money from broker accounts. This vulnerability has been exploited since April 2023.

The report confirmed that the malicious archives found their way onto at least eight public trading forums infecting at least 130 devices, however, the victim’s financial losses were unknown.

WinRar exploit infection chain. Source: Group-IB

On execution, the script launches a self-extracting (SFX) archive that infects the target computer with various malware strains, such as the DarkMe, GuLoader, and Remcos RAT.

These provide the attacker with remote access privileges on the infected computer. DarkMe malware has previously been used in crypto and financially motivated attacks.

The researchers notified RARLABS which patched the zero-day vulnerability in WinRAR version 6.23, released on Aug. 2.

Related: Crypto investors under attack by new malware, reveals Cisco Talos

In August, smartphone giant BlackBerry identified several malware families that actively aimed to hijack computers to mine or steal cryptocurrencies.

The same month also revealed a newly discovered remote access tool called HVNC (Hidden Virtual Network Computer) that can enable hackers to compromise Apple operating systems was found on sale on the dark web.

Magazine: Should crypto projects ever negotiate with hackers? Probably

Read Entire Article
spot_img

Related Posts

Crypto Market Downturn Hits Coinbase, Microstrategy, and Mining Stocks Hard

During the widespread downturn in the cryptocurrency markets, publicly listed companies within the sector such as Coinbase, Microstrategy, and bitcoin mining enterprises have experienced notable

Machine Learning Algorithm Predicts Dogecoin Price For May 2024

As April comes to a bearish close, expectations for Dogecoin in May are not exactly bullish, especially as the crypto market has continued to fall DOGE has been one of the main losers during this

Bitcoin faces potential miner capitulation as hash rate continues to drop

Quick Take CryptoSlate’s analysis sheds light on the anticipated hash rate adjustment, with historical trends indicating a potential 20% decrease post-halving Past cycles reflect significant

Restrictive OTC regulations for institutions amid Hong Kong ETF launch – BitGo APAC director

Hong Kong has emerged as a key player in the race to become Asia’s premier crypto hub, as it launched the region’s first spot crypto ETFs on April 30 with a day-one inflow of over $130

Bitcoin Technical Analysis: Uncertainty Looms as Bearish Patterns Persist

Bitcoin’s technical analysis reveals a protracted bearish trend, reflecting significant selling pressure and resistance to upward movement With today’s price standing between $57,505

Pro-XRP Lawyer Deaton Accuses SEC’s Gensler Of ‘Infecting’ Ethical Standards

In a searing critique, John E Deaton, a prominent legal advocate for XRP, has issued a forceful condemnation of SEC Chairman Gary Gensler, accusing him of undermining ethical standards and fostering
- Advertisement -spot_img