WinRAR Exploit with Social Engineering and Encryption - CVE-2018-20250
released on 2019-02-27 @ 10:04:41 PM
On February 22, 360 Threat Intelligence Center captured the first ACE archive to spread malware in the wild through exploiting WinRAR vulnerability (CVE-2018-20250).
They captured multiple samples using this vulnerability in the following days and also observed some potential APT attacks. Obviously, attackers use this exploit in a more delicate way. For example, they embed lots of pictures and lure the target to decompress since those cannot be previewed in the compressed archive, encrypt the malicious ACE file before delivering, and so on.
It can be seen that attacks using this vulnerability are in the early stages of an outbreak, many other malware including worms may get embedded as payload in the future to cause more damages.