March 19, 2019 By Shane Schick 2 min read

More than 100 unique exploits of a WinRAR bug have been identified since security researchers discovered a 19-year-old vulnerability in the file compression system.

Antivirus products may not immediately recognize persistent malware installed via the code execution flaw in the Windows-based utility, which was initially uncovered by Check Point. In a recent blog post, McAfee researchers noted that attackers are mostly targeting U.S. users, hoping to reach them before they install a patch that was released late last month.

WinRAR Bug Puts 500 Million Users at Risk

With a series of screenshots, McAfee illustrated a typical exploit that leveraged an illegal version of “thank u, next,” the hit song by pop singer Ariana Grande. Threat actors set up a payload containing malware in the Startup folder while a version of WinRAR containing the flaw extracted the MP3 file to a download folder.

User Account Control does not apply in this case, the researchers added, which means a user wouldn’t get a signal that the payload was installed. Once the system reboots, the malware starts running.

WinRAR is a popular tool with an estimated 500 million users, which means the scope for threat actors to pursue exploits is particularly large. It’s also common to see bootlegs such as the Ariana Grande song widely available on underground forums and torrent sites, which can provide plenty of opportunity to take advantage of the flaw.

No, Thank You: How to Avoid the WinRAR Bug

While the best recourse for most users is to simply avoid suspicious downloads and apply the patched version, WinRAR 5.70, that may not be enough to protect entire organizations. According to IBM experts, there is often a disconnect between IT security teams and operations teams when it comes to information related to critical software patches.

With the right patch posture reporting tools, security professionals can conduct a comprehensive assessment of devices that may be vulnerable to something like the WinRAR bug, then filter and sort data based on the most appropriate remediation priority. Given how quickly threat actors are trying to capitalize on this flaw, there’s no time to lose.

More from

How to craft a comprehensive data cleanliness policy

3 min read - Practicing good data hygiene is critical for today’s businesses. With everything from operational efficiency to cybersecurity readiness relying on the integrity of stored data, having confidence in your organization’s data cleanliness policy is essential.But what does this involve, and how can you ensure your data cleanliness policy checks the right boxes? Luckily, there are practical steps you can follow to ensure data accuracy while mitigating the security and compliance risks that come with poor data hygiene.Understanding the 6 dimensions of…

2024 roundup: Top data breach stories and industry trends

3 min read - With 2025 on the horizon, it’s important to reflect on the developments and various setbacks that happened in cybersecurity this past year. While there have been many improvements in security technologies and growing awareness of emerging cybersecurity threats, 2024 was also a hard reminder that the ongoing fight against cyber criminals is far from over.We've summarized this past year's top five data breach stories and industry trends, with key takeaways from each that organizations should note going into the following…

Black Friday chaos: The return of Gozi malware

4 min read - On November 29th, 2024, Black Friday, shoppers flooded online stores to grab the best deals of the year. But while consumers were busy filling their carts, cyber criminals were also seizing the opportunity to exploit the shopping frenzy. Our system detected a significant surge in Gozi malware activity, targeting financial institutions across North America. The Black Friday connection Black Friday creates an ideal environment for cyber criminals to thrive. The combination of skyrocketing transaction volumes, a surge in online activity…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today