March 19, 2019 By Shane Schick 2 min read

More than 100 unique exploits of a WinRAR bug have been identified since security researchers discovered a 19-year-old vulnerability in the file compression system.

Antivirus products may not immediately recognize persistent malware installed via the code execution flaw in the Windows-based utility, which was initially uncovered by Check Point. In a recent blog post, McAfee researchers noted that attackers are mostly targeting U.S. users, hoping to reach them before they install a patch that was released late last month.

WinRAR Bug Puts 500 Million Users at Risk

With a series of screenshots, McAfee illustrated a typical exploit that leveraged an illegal version of “thank u, next,” the hit song by pop singer Ariana Grande. Threat actors set up a payload containing malware in the Startup folder while a version of WinRAR containing the flaw extracted the MP3 file to a download folder.

User Account Control does not apply in this case, the researchers added, which means a user wouldn’t get a signal that the payload was installed. Once the system reboots, the malware starts running.

WinRAR is a popular tool with an estimated 500 million users, which means the scope for threat actors to pursue exploits is particularly large. It’s also common to see bootlegs such as the Ariana Grande song widely available on underground forums and torrent sites, which can provide plenty of opportunity to take advantage of the flaw.

No, Thank You: How to Avoid the WinRAR Bug

While the best recourse for most users is to simply avoid suspicious downloads and apply the patched version, WinRAR 5.70, that may not be enough to protect entire organizations. According to IBM experts, there is often a disconnect between IT security teams and operations teams when it comes to information related to critical software patches.

With the right patch posture reporting tools, security professionals can conduct a comprehensive assessment of devices that may be vulnerable to something like the WinRAR bug, then filter and sort data based on the most appropriate remediation priority. Given how quickly threat actors are trying to capitalize on this flaw, there’s no time to lose.

More from

The major hardware flaw in Apple M-series chips

3 min read - The “need for speed” is having a negative impact on many Mac users right now. The Apple M-series chips, which are designed to deliver more consistent and faster performance than the Intel processors used in the past, have a vulnerability that can expose cryptographic keys, leading an attacker to reveal encrypted data. This critical security flaw, known as GoFetch, exploits a vulnerability found in the M-chips data memory-dependent prefetcher (DMP). DMP’s benefits and vulnerabilities DMP predicts memory addresses that the…

NIST’s role in the global tech race against AI

4 min read - Last year, the United States Secretary of Commerce announced that the National Institute of Standards and Technology (NIST) has been put in charge of launching a new public working group on artificial intelligence (AI) that will build on the success of the NIST AI Risk Management Framework to address this rapidly advancing technology.However, recent budget cuts at NIST, along with a lack of strategy implementation, have called into question the agency’s ability to lead this critical effort. Ultimately, the success…

Researchers develop malicious AI ‘worm’ targeting generative AI systems

2 min read - Researchers have created a new, never-seen-before kind of malware they call the "Morris II" worm, which uses popular AI services to spread itself, infect new systems and steal data. The name references the original Morris computer worm that wreaked havoc on the internet in 1988.The worm demonstrates the potential dangers of AI security threats and creates a new urgency around securing AI models.New worm utilizes adversarial self-replicating promptThe researchers from Cornell Tech, the Israel Institute of Technology and Intuit, used what’s…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today