{"id":1193726,"date":"2023-10-18T12:41:00","date_gmt":"2023-10-18T16:41:00","guid":{"rendered":"https:\/\/www.prime-wow.com\/?p=1193726"},"modified":"2023-10-18T12:41:00","modified_gmt":"2023-10-18T16:41:00","slug":"russia-and-china-backed-hackers-are-exploiting-winrar-zero-day-bug-google-says","status":"publish","type":"post","link":"https:\/\/www.prime-wow.com\/?p=1193726","title":{"rendered":"Russia and China-backed Hackers Are Exploiting WinRAR Zero-Day Bug, Google Says"},"content":{"rendered":"<p>Google security researchers say they have found evidence that government-backed hackers linked to Russia and China are exploiting a since-patched vulnerability in WinRAR, the popular shareware archiving tool for Windows. From a report: The WinRAR vulnerability, first discovered by cybersecurity company Group-IB earlier this year and tracked as CVE-2023-38831, allows attackers to hide malicious scripts in archive files that masquerade as seemingly innocuous images or text documents. Group-IB said the flaw was exploited as a zero-day &#8212; since the developer had zero time to fix the bug before it was exploited &#8212; as far back as April to compromise the devices of at least 130 traders. <\/p>\n<p>Rarlab, which makes the archiving tool, released an updated version of WinRAR (version 6.23) on August 2 to patch the vulnerability. Despite this, Google&#8217;s Threat Analysis Group (TAG) said this week that its researchers have observed multiple government-backed hacking groups exploiting the security flaw, noting that &#8220;many users&#8221; who have not updated the app remain vulnerable. In research shared with TechCrunch ahead of its publication, TAG says it has observed multiple campaigns exploiting the WinRAR zero-day bug, which it has tied to state-backed hacking groups with links to Russia and China.<\/p>\n<p \/>\n<div class=\"share_submission\" style=\"position:relative\">\n<a class=\"slashpop\" href=\"http:\/\/twitter.com\/home?status=Russia+and+China-backed+Hackers+Are+Exploiting+WinRAR+Zero-Day+Bug%2C+Google+Says%3A+https%3A%2F%2Fit.slashdot.org%2Fstory%2F23%2F10%2F18%2F1640258%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter\"><img decoding=\"async\" src=\"https:\/\/www.prime-wow.com\/wp-content\/uploads\/2023\/10\/twitter_icon_large-689.png\" \/><\/a><br \/>\n<a class=\"slashpop\" href=\"http:\/\/www.facebook.com\/sharer.php?u=https%3A%2F%2Fit.slashdot.org%2Fstory%2F23%2F10%2F18%2F1640258%2Frussia-and-china-backed-hackers-are-exploiting-winrar-zero-day-bug-google-says%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook\"><img decoding=\"async\" src=\"https:\/\/www.prime-wow.com\/wp-content\/uploads\/2023\/10\/facebook_icon_large-344.png\" \/><\/a><\/p>\n<\/div>\n<p><a href=\"https:\/\/it.slashdot.org\/story\/23\/10\/18\/1640258\/russia-and-china-backed-hackers-are-exploiting-winrar-zero-day-bug-google-says?utm_source=rss1.0moreanon&amp;utm_medium=feed\">Read more of this story<\/a> at Slashdot.<\/p>\n<p>&#013;<br \/>\n&#013;<br \/>\nSource: Slashdot &#8211; <a href=\"https:\/\/it.slashdot.org\/story\/23\/10\/18\/1640258\/russia-and-china-backed-hackers-are-exploiting-winrar-zero-day-bug-google-says?utm_source=rss1.0mainlinkanon&amp;utm_medium=feed\" target=\"_blank\" rel=\"noopener\">Russia and China-backed Hackers Are Exploiting WinRAR Zero-Day Bug, Google Says<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Google security researchers say they have found evidence that government-backed hackers linked to Russia and China are exploiting a since-patched vulnerability in WinRAR, the popular shareware archiving tool for Windows. From a report: The WinRAR vulnerability, first discovered by cybersecurity &hellip; <a href=\"https:\/\/www.prime-wow.com\/?p=1193726\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":1193727,"comment_status":"open","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[101,110],"tags":[100],"class_list":["post-1193726","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-slashdot","category-unfiltered-rss","tag-slashdot"],"_links":{"self":[{"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=\/wp\/v2\/posts\/1193726","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1193726"}],"version-history":[{"count":0,"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=\/wp\/v2\/posts\/1193726\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=\/wp\/v2\/media\/1193727"}],"wp:attachment":[{"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1193726"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1193726"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1193726"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}