• News/
  • https://www.bleepingcomputer.com/news/security/winrar-zero-day-exploited-since-april-to-hack-trading-accounts/

WinRAR zero-day exploited since April to hack trading accounts

BleepingComputer
·
Published Aug 23, 2023
·
Updated

A WinRar zero-day vulnerability tracked as CVE-2023-38831 was actively exploited to install malware when clicking on harmless files in an archive, allowing the hackers to breach online cryptocurrency trading accounts. The vulnerability has been under active exploitation since April 2023, helping distribute various malware families, including DarkMe, GuLoader, and Remcos RAT. The WinRAR zero-day vulnerability allowed the threat actors to create malicious .RAR and .ZIP archives that displayed seemingly innocuous files, such as JPG (.jpg) images, text files (.txt), or PDF (.pdf) documents. However, when a user opens the document, the flaw will cause a script to be executed that installs malware on the device. BleepingComputer tested a malicious archive shared by Group-IB, who discovered the campaign, and simply double-clicking on a PDF caused a CMD script to be executed to install malware. The zero-day was fixed in WinRAR version 6.23, released on August 2, 2023, which also resolves several other security issues, including CVE-2023-40477, a flaw that can trigger command execution upon opening a specially crafted RAR file. In a report released today, researchers from Group-IB said they discovered the WinRAR zero-day being used to target cryptocurrency and stock trading forums, where the hackers pretended to be other enthusiasts sharing their trading strategies. These forum posts contained links to specially crafted WinRAR ZIP or RAR archives that pretended to include the shared ...

Read full article

Affected Software

1 affected component
RARLAB WinRAR<6.23

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a zero-day vulnerability in WinRAR that has been exploited to hack cryptocurrency trading accounts.

2

What specific vulnerability is mentioned in the article?

The vulnerability mentioned is CVE-2023-38831, which allows malware installation via seemingly harmless compressed files.

3

How long has the WinRAR vulnerability been exploited?

The WinRAR vulnerability has been actively exploited since April 2023.

4

What software is affected by this vulnerability?

The affected software is WinRAR, specifically versions up to 6.23.

5

What are the security implications of the exploited vulnerability?

The exploited vulnerability enables hackers to breach online cryptocurrency trading accounts, potentially leading to financial loss for users.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203