Tuesday, April 29, 2025
HomeCyber AttackAlert !! Hackers Launching New JNEC.a Ransomware via WinRAR Exploits - Do...

Alert !! Hackers Launching New JNEC.a Ransomware via WinRAR Exploits – Do not Pay

Published on

SIEM as a Service

Follow Us on Google News

A brand new JNEC.a ransomware spreading via recently discovered WinRAR vulnerability exploit to compromise windows computer & demand the ransom amount.

This exploits leverage the recently discovered WinRAR ACE code injection vulnerability, since then attackers continuously exploiting the vulnerability to intrude the targeted system in various ways.

WinRAR is the worlds most popular Compression tool that used over 500 million users around the world.

- Advertisement - Google News

The 19-year-old vulnerability was disclosed by checkpoint security researchers last week, the vulnerability resides in the WinRAR UNACEV2.DLL library.

Since the vulnerability has been already patched, attacker aiming to exploit and compromise the unpatched vulnerable systems.

JNEC.a Ransomware payload stored in the compressed RAR file archive, once the file will be decompressed by the victim, it opens up a corrupted and incomplete female picture.

Meanwhile, in the background JNEC.a Ransomware drops into the victim’s system and starts its process to encrypt the files and lock the system.

Malware Authors choosing very unusual decryption key delivery method by providing a Gmail ID, which should be used by victims to request the decryption key.

Researchers from 360 Threat Intelligence Center initially uncovered this JNEC.a Ransomware sample with the file name (vk_4221345.rar) and confirm that the ransomware spread by #WinRAR exploit (#CVE-2018-20250).

Once the system exploited successfully, the encryption routine starts to lock the file and displays the ransom notes, that contains steps to recover the decryption key.

Also Read: Ransomware Attack Response and Mitigation Checklist

Ransom note also contains a piece of detailed information about the number of encrypted files in the system and ransom demand, which needs to pay through bitcoin.

In this case, victims need to create a specific mailbox for the given Gmail ID to receive the decryption key.

Attackers claim that they will reach the victims back once the victims successfully made the payment to the bitcoin address that mentioned in the ransom notes.

Attackers demand 0.05 BTC ($198 USD) from each victim who all are infected by this JNEC.a Ransomware and attackers will contact the victims once they received the payment.

This sample is tested in VirusTotal where 28 engines detected this file as a malicious threat in various names.

Security researcher Michael Gillespie analyzed this sample and confirm that, due to the bug that exists in this ransomware, no one can decrypt the file even the ransomware developer.

All the WinRAR users are advised to update the current patched version,
WinRAR 5.70 to avoid such attacks and also avoid to open the unknown files.

IOC

MD59ebe2ee958ddd61c93400293d6903ab0

SHA-1bf9ec6fe2352faddb147ebe8369ccaa76f8c60e7

Learn: Certified Cyber Threat Intelligence Analysts courses

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

JokerOTP Platform Linked to 28,000+ Phishing Attacks Dismantled

Law enforcement agencies from the UK and the Netherlands have dismantled the notorious JokerOTP...

Windows Server 2025 Gets Hotpatching Support Beginning July 1, 2025

Microsoft announced that hotpatching support for Windows Server 2025 will become generally available as...

Critical Linux Kernel Flaw (CVE-2025-21756) Allows Privilege Escalation

A newly disclosed vulnerability in the Linux kernel, tracked as CVE-2025-21756 and dubbed “Attack of the...

Massive Attack: 4,800+ IPs Used to Target Git Configuration Files

A recent surge in cyber reconnaissance has put thousands of organizations at risk after...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

RansomHub Ransomware Deploys Malware to Breach Corporate Networks

The eSentire’s Threat Response Unit (TRU) in early March 2025, a sophisticated cyberattack leveraging...

Fog Ransomware Reveals Active Directory Exploitation Tools and Scripts

Cybersecurity researchers from The DFIR Report’s Threat Intel Group uncovered an open directory hosted...

Advanced Multi-Stage Carding Attack Hits Magento Site Using Fake GIFs and Reverse Proxy Malware

A multi-stage carding attack has been uncovered targeting a Magento eCommerce website running an...