• News/
  • bleepingcomputer-20230823135326

WinRAR zero-day exploited since April to hack trading accounts

BleepingComputer
·
Published Aug 23, 2023
·
Updated

A WinRar zero-day vulnerability tracked as CVE-2023-38831 was actively exploited to install malware when clicking on harmless files in an archive, allowing the hackers to breach online cryptocurrency trading accounts. The vulnerability has been under active exploitation since April 2023, helping distribute various malware families, including DarkMe, GuLoader, and Remcos RAT. The WinRAR zero-day vulnerability allowed the threat actors to create malicious .RAR and .ZIP archives that displayed seemingly innocuous files, such as JPG (.jpg) images, text files (.txt), or PDF (.pdf) documents. However, when a user opens the document, the flaw will cause a script to be executed that installs malware on the device. BleepingComputer tested a malicious archive shared by Group-IB, who discovered the campaign, and simply double-clicking on a PDF caused a CMD script to be executed to install malware. The zero-day was fixed in WinRAR version 6.23, released on August 2, 2023, which also resolves several other security issues, including CVE-2023-40477, a flaw that can trigger command execution upon opening a specially crafted RAR file. In a report released today, researchers from Group-IB said they discovered the WinRAR zero-day being used to target cryptocurrency and stock trading forums, where the hackers pretended to be other enthusiasts sharing their trading strategies. These forum posts contained links to specially crafted WinRAR ZIP or RAR archives that pretended to include the shared ...

Read full article

Affected Software

1 affected component
WinRAR WinRAR<6.23
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a zero-day vulnerability in WinRAR that has been exploited to hack cryptocurrency trading accounts.

2

What security implications are discussed in the article?

The security implications include the risk of malware installation through apparently harmless files in archives, leading to unauthorized access to online accounts.

3

What vulnerability is being highlighted in this article?

The vulnerability is tracked as CVE-2023-38831 and has been actively exploited since April 2023.

4

Which software is affected by this zero-day vulnerability?

The affected software is WinRAR.

5

What kind of accounts have been breached due to this exploitation?

The exploitation has led to breaches of online cryptocurrency trading accounts.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203