After Sandworm and APT28 (known as Fancy Bear), another state-sponsored Russian hacker group, APT29, is leveraging the CVE-2023-38831 vulnerability in WinRAR for cyberattacks. APT29 is tracked under different names (UNC3524,/NobleBaron/Dark Halo/NOBELIUM/Cozy Bear/CozyDuke, SolarStorm) and has been targeting embassy entities with a BMW car sale lure. The CVE-2023-38831 security flaw affects WinRAR versions before 6.23 and allows crafting .RAR and .ZIP archives that can execute in the background code prepared by the attacker for malicious purposes. The vulnerability has been exploited as a zero-day since April by threat actors targeting cryptocurrency and stock trading forums. In a report this week, the Ukrainian National Security and Defense Council (NDSC) says that APT29 has been using a malicious ZIP archive that runs a script in the background to show a PDF lure and to download PowerShell code that downloads and executes a payload. The malicious archive is called “DIPLOMATIC-CAR-FOR-SALE-BMW.pdf” and targeted multiple countries on the European continent, including Azerbaijan, Greece, Romania, and Italy. APT29 has used the BMW car ad phishing lure before to target diplomats in Ukraine during a campaign in May that delivered ISO payloads through the HTML smuggling technique. In these attacks, the Ukrainian NDSC says that APT29 combined the old phishing tactic with a novel technique to enable communication with the malicious server. NDSC says that the Russian hackers used a ...
Russian hackers use Ngrok feature and WinRAR exploit to attack embassies
BleepingComputer
·Ionut Ilascu
·Published Nov 19, 2023
·Updated
Affected Software
1 affected component
WinRAR WinRAR=6.23
Frequently Asked Questions
1
What is the main focus of the article?
The article details how Russian hacker group APT29 is exploiting the WinRAR CVE-2023-38831 vulnerability in cyberattacks against embassies.
2
What specific vulnerability is highlighted in the attacks?
The attacks leverage the CVE-2023-38831 vulnerability in WinRAR version 6.23.
3
Who are the attackers mentioned in the article?
The attackers are APT29, a state-sponsored Russian hacker group also known as UNC3524 or Cozy Bear.
4
What methods are used by attackers in these cyberattacks?
APT29 is utilizing a feature of Ngrok alongside the WinRAR exploit to facilitate their attacks.
5
What types of organizations are being targeted in these attacks?
The targeted organizations include various embassies, indicating a focus on diplomatic entities.