Sunday, November 24, 2024
HomeComputer SecurityFirst Malware Campaign Exploits WinRAR ACE vulnerability To Hack Windows Computer

First Malware Campaign Exploits WinRAR ACE vulnerability To Hack Windows Computer

Published on

Researchers have detected the first malspam campaign that delivers a malicious RAR archive to infect victim’s computer exploiting the WinRAR ACE vulnerability.

The 19-year-old vulnerability was disclosed by checkpoint security researchers last week, the vulnerability resides in the WinRAR UNACEV2.DLL library.

This vulnerability can be exploited by an attacker with specially crafted ACE archive and to extract the file in windows startup folder to gain the persistence and to get launched automatically once the user logged in to the computer.

- Advertisement - SIEM as a Service

First Malspam Campaign

360 Threat intelligence center detected a malspam campaign that delivers a malcious RAR archive by exploiting this vulnerability.The backdoor is generated MSF and it extracts to user’s startup folder.

Based on analysis the malware fails to execute due to lack of permissions if UAC is running in the machine, the extraction fails with the error “Access is denied” and “operation failed”.

Training Course: Certified Cyber Threat Intelligence Analysts course that we’ll introduce you to the 8 phases of threat intelligence.

If the UAC is disabled or the WinRAR running with the admin privileges then the malware will get extract to the user’s Startup folder C:\ProgramData\Microsoft\Windows\StartMenu\Programs\Startup\CMSTray.exe and it will execute with the user’s next login.

  • The malware gets extracted to CMSTray.exe and it will be launched upon next login
  • Once the malware launched it copies the CMSTray.exe file to %Temp%\wbssrv.exe and the executable get’s executed.
  • Upon execution, it connects with the following 138.204.171.108 and downloads various tools including the including the asynchronous post-exploitation agent Cobalt Strike Beacon.
  • Once the DLL got loaded the attackers able to obtain remote connection over the victim’s machine and run’s various commands.

If you have not yet updated the WinRAR, it’s time to update with the latest version of the WinRAR(WinRAR 5.70 beta 1).

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

Nearest Neighbor Attacks: Russian APT Hack The Target By Exploiting Nearby Wi-Fi Networks

Recent research has revealed that a Russian advanced persistent threat (APT) group, tracked as...

240+ Domains Used By PhaaS Platform ONNX Seized by Microsoft

Microsoft's Digital Crimes Unit (DCU) has disrupted a significant phishing-as-a-service (PhaaS) operation run by...

Russian TAG-110 Hacked 60+ Users With HTML Loaded & Python Backdoor

The Russian threat group TAG-110, linked to BlueDelta (APT28), is actively targeting organizations in...

Earth Kasha Upgraded Their Arsenal With New Tactics To Attack Organizations

Earth Kasha, a threat actor linked to APT10, has expanded its targeting scope to...

Free Webinar

Protect Websites & APIs from Malware Attack

Malware targeting customer-facing websites and API applications poses significant risks, including compliance violations, defacements, and even blacklisting.

Join us for an insightful webinar featuring Vivek Gopalan, VP of Products at Indusface, as he shares effective strategies for safeguarding websites and APIs against malware.

Discussion points

Scan DOM, internal links, and JavaScript libraries for hidden malware.
Detect website defacements in real time.
Protect your brand by monitoring for potential blacklisting.
Prevent malware from infiltrating your server and cloud infrastructure.

More like this

Nearest Neighbor Attacks: Russian APT Hack The Target By Exploiting Nearby Wi-Fi Networks

Recent research has revealed that a Russian advanced persistent threat (APT) group, tracked as...

240+ Domains Used By PhaaS Platform ONNX Seized by Microsoft

Microsoft's Digital Crimes Unit (DCU) has disrupted a significant phishing-as-a-service (PhaaS) operation run by...

Russian TAG-110 Hacked 60+ Users With HTML Loaded & Python Backdoor

The Russian threat group TAG-110, linked to BlueDelta (APT28), is actively targeting organizations in...