Close Menu
Savannah HeraldSavannah Herald
  • Home
  • News
    • Local
    • State
    • National
    • World
    • HBCUs
  • Events
  • Directories
  • Weather
  • Traffic
  • Sports
  • Politics
  • Lifestyle
    • Faith
    • Senior Living
    • Health
    • Travel
    • Beauty
    • Fashion
    • Food
    • Art & Literature
  • Business
    • Real Estate
    • Entertainment
    • Investing
    • Education
  • Guides
    • Juneteenth Guide
    • Black History Savannah
    • MLK Guide Savannah
We're Social
  • Twitter
  • Facebook
  • YouTube

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

Trending
  • Actor, avid golfer Michael Peña joins First Tee as Brand Ambassador – First Tee – Savannah
  • Bacon And Ham Hash Brown Skillet🍳
  • Margo’s Got Money Troubles Recap, Episode 4: ‘Buddies’
  • Woodville-Tompkins girls' soccer wins first playoff game in school history
  • What a Patients’ Bill of Rights Could Mean for Black Women
  • Hiring Mistakes to Avoid in the Tech Industry
  • Georgia Trend Daily – April 22, 2026
  • Sandy Springs art show reclaims what we throw away
Facebook X (Twitter) Instagram YouTube
Login
Savannah HeraldSavannah Herald
  • Home
  • News
    • Local
    • State
    • National
    • World
    • HBCUs
  • Events
  • Directories
  • Weather
  • Traffic
  • Sports
  • Politics
  • Lifestyle
    • Faith
    • Senior Living
    • Health
    • Travel
    • Beauty
    • Fashion
    • Food
    • Art & Literature
  • Business
    • Real Estate
    • Entertainment
    • Investing
    • Education
  • Guides
    • Juneteenth Guide
    • Black History Savannah
    • MLK Guide Savannah
Savannah HeraldSavannah Herald
Home » High-severity WinRAR 0-day exploited for weeks by 2 groups
Tech

High-severity WinRAR 0-day exploited for weeks by 2 groups

Savannah HeraldBy Savannah HeraldSeptember 3, 20253 Mins Read
Facebook Twitter Pinterest LinkedIn WhatsApp Reddit Tumblr Email
High-severity WinRAR 0-day exploited for weeks by 2 groups
Share
Facebook Twitter LinkedIn Pinterest Email

Tech Trends & Innovation: The Latest in Tech News

BI.ZONE said the Paper Werewolf delivered the exploits in July and August through archives attached to emails impersonating employees of the All-Russian Research Institute. The ultimate goal was to install malware that gave Paper Werewolf access to infected systems.

While the discoveries by ESET and BI.ZONE were independent of each other, it’s unknown if the groups exploiting the vulnerabilities are connected or acquired the knowledge from the same source. BI.ZONE speculated that Paper Werewolf may have procured the vulnerabilities in a dark market crime forum.

ESET said the attacks it observed followed three execution chains. One chain, used in attacks targeting a specific organization, executed a malicious DLL file hidden in an archive using a method known as COM hijacking that caused it to be executed by certain apps such as Microsoft Edge. It looked like this:



Illustration of the execution chain installing Mythic Agent.

Credit:
ESET

Illustration of the execution chain installing Mythic Agent.


Credit:

ESET

The DLL file in the archive decrypted embedded shellcode, which went on to retrieve the domain name for the current machine and compare it with a hardcoded value. When the two matched, the shellcode installed a custom instance of the Mythic Agent exploitation framework.

A second chain ran a malicious Windows executable to deliver a final payload installing SnipBot, a known piece of RomCom malware. It blocked some attempts at being forensically analyzed by terminating when opened in an empty virtual machine or sandbox, a practice common among researchers. A third chain made use of two other known pieces of RomCom malware, one known as RustyClaw and the other as Melting Claw.

WinRAR vulnerabilities have previously been exploited to install malware. One code-execution vulnerability from 2019 came under wide exploitation in 2019 shortly after being patched. In 2023, a WinRAR zero-day was exploited for more than four months before the attacks were detected.

Besides its massive user base, WinRAR makes a perfect vehicle for spreading malware because the utility has no automated mechanism for installing new updates. That means users must actively download and install patches on their own. What’s more, ESET said Windows versions of the command-line utilities UnRAR.dll and the portable UnRAR source code are also vulnerable. People should steer clear of all WinRAR versions prior to 7.13, which, at the time this post went live, was the most current. It has fixes for all known vulnerabilities, although given the seemingly unending stream of WinRAR zero-days, it isn’t much of an assurance.

Read the full article from the original source


AI and Machine Learning artificial intelligence Consumer Electronics Cybersecurity Updates Data Privacy Digital Trends Enterprise Technology Future of Work Gadget Reviews Green Tech Mobile Tech Robotics News Science and Technology Silicon Valley News Software Development Startups and Tech Tech Industry Insights Tech Innovation Tech Policy Technology News
Share. Facebook Twitter Pinterest LinkedIn WhatsApp Reddit Tumblr Email
Savannah Herald
  • Website

Related Posts

Tech April 22, 2026

Hiring Mistakes to Avoid in the Tech Industry

Tech April 22, 2026

Michael and Susan Dell give $1B+ to UT Austin for AI-native hospital

Tech April 21, 2026

The RAM Shortage Crisis: How AI Demand is Reshaping Memory Markets Until 2027 and Beyond

Tech April 20, 2026

Seasonal Switch 2 sales show significant slowing as annual cycle sunsets

Tech April 19, 2026

Best Meta Glasses (2026): Ray-Ban, Oakley, AR

Tech April 19, 2026

I Found My Dad’s McDonald’s Collectibles. I Decided to Sell Them.

Comments are closed.

Don't Miss
Education December 7, 2025By Savannah Herald04 Mins Read

Confusion over college scholarship opportunities with New Birth

December 7, 2025

From Campus to Classroom: Stories That Shape Education New Birth hosted what it called its…

How a SCOTUS Decision on Birthright Citizenship Could Impact Education Access

April 5, 2026

Elon Musk impersonators scam victims with fake Tesla and cash giveaways

November 1, 2025

Mrs. Mentoria German Bradley

November 11, 2025

Don’t Sleep On E.L.F. Skincare Products

October 28, 2025
Archives
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025
  • April 2025
  • March 2025
  • February 2025
  • January 2025
  • December 2024
Categories
  • Art & Literature
  • Beauty
  • Black History
  • Business
  • Climate
  • Education
  • Employment
  • Entertainment
  • Faith
  • Fashion
  • Food
  • Gaming
  • Georgia Politics
  • HBCUs
  • Health
  • Health Inspections
  • Home & Garden
  • Investing
  • Local
  • Lowcountry News
  • National
  • National Opinion
  • News
  • Obituaries
  • Politics
  • Real Estate
  • Science
  • Senior Living
  • Sports
  • SSU Homecoming 2024
  • State
  • Tech
  • Transportation
  • Travel
  • World
Savannah Herald Newsletter

Subscribe to Updates

A round up interesting pic’s, post and articles in the C-Port and around the world.

About Us
About Us

The Savannah Herald is your trusted source for the pulse of Coastal Georgia and the Low County of South Carolina. We're committed to delivering timely news that resonates with the African American community.

From local politics to business developments, we're here to keep you informed and engaged. Our mission is to amplify the voices and stories that matter, shining a light on our collective experiences and achievements.
We cover:
🏛️ Politics
💼 Business
🎭 Entertainment
🏀 Sports
🩺 Health
💻 Technology
Savannah Herald: Savannah's Black Voice 💪🏾

Our Picks

Trump admin to revoke dozens of food product standards

August 28, 2025

City to Host Holiday Safety Extravaganza • Savannah, GA

December 17, 2025

Ms. Betty Ann Bynes | 11/21/2025

December 24, 2025

Hip-Hop Music Producer Hitman Howie Tee Dead At 61

August 4, 2025

Obituary for Dennis Darquan Rogers

December 24, 2025
Categories
  • Art & Literature
  • Beauty
  • Black History
  • Business
  • Climate
  • Education
  • Employment
  • Entertainment
  • Faith
  • Fashion
  • Food
  • Gaming
  • Georgia Politics
  • HBCUs
  • Health
  • Health Inspections
  • Home & Garden
  • Investing
  • Local
  • Lowcountry News
  • National
  • National Opinion
  • News
  • Obituaries
  • Politics
  • Real Estate
  • Science
  • Senior Living
  • Sports
  • SSU Homecoming 2024
  • State
  • Tech
  • Transportation
  • Travel
  • World
  • Privacy Policies
  • Disclaimers
  • Terms and Conditions
  • About Us
  • Contact Us
  • Opt-Out Preferences
  • Accessibility Statement
Copyright © 2002-2026 Savannahherald.com All Rights Reserved. A Veteran-Owned Business

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
Ad Blocker Enabled!
Ad Blocker Enabled!
Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.

Sign In or Register

Welcome Back!

Login below or Register Now.

Lost password?

Register Now!

Already registered? Login.

A password will be e-mailed to you.