{"id":26231,"date":"2019-03-28T11:39:30","date_gmt":"2019-03-28T15:39:30","guid":{"rendered":"https:\/\/www.kaspersky.com\/blog\/?p=26231"},"modified":"2019-11-15T06:27:45","modified_gmt":"2019-11-15T11:27:45","slug":"update-winrar-now","status":"publish","type":"post","link":"https:\/\/www.kaspersky.com\/blog\/update-winrar-now\/26231\/","title":{"rendered":"Using WinRAR? Install this update right away"},"content":{"rendered":"<p>Everybody knows that clicking on EXE files can be dangerous. Some people are even aware of the potential risks of opening MS Office files, which can also contain malware. But what can go wrong if you simply unpack a WinRAR archive? Actually, quite a lot.<\/p>\n<p>If you are one of the 500 million people worldwide using WinRAR, you are a perfect target for hijackers. It was recently discovered that every version of WinRAR released in the last 19 years has a critical bug that allows cybercriminals into your computer. Now more than 100 ways to exploit it <a target=\"_blank\" href=\"https:\/\/www.zdnet.com\/article\/100-unique-exploits-and-counting-for-latest-winrar-security-bug\/\" rel=\"noopener noreferrer nofollow\">have been identified <\/a>\u2014 and that number keeps going up.<\/p>\n<h2>How the 19-year-old WinRAR bug works<\/h2>\n<p>The security flaw enables hijackers to create malicious RAR archives. As soon as this archive is unpacked, a malicious executable file is silently extracted into the Startup folder. On the next reboot this file will be automatically launched, thus infecting your computer with whatever payload the file contains.<\/p>\n<p>To pass undetected even by the most cautious of us, the malefactors usually give this EXE file very innocent-looking names, such as GoogleUpdate.exe.<\/p>\n<p>It should go without saying that malicious archives and the e-mails that contain them are designed to make the victim push the extract button. The lures <a target=\"_blank\" href=\"https:\/\/ti.360.net\/blog\/articles\/upgrades-in-winrar-exploit-with-social-engineering-and-encryption\/\" rel=\"noopener noreferrer nofollow\">vary greatly<\/a>. Sometimes hackers opt for bait labeled as adult images, sometimes they compose an extremely attractive job offer, sometimes they alert you of a terrorist attack risk. In some cases, malefactors pretend to send some technical documents, or inform you about recent changes to local legislation. Some even invite you to download a pirated copy of a hit album, for example, by <a target=\"_blank\" href=\"https:\/\/www.pcmag.com\/news\/367212\/bootleg-ariana-grande-album-used-to-spread-malware-via-winra\" rel=\"noopener noreferrer nofollow\">Ariana Grande<\/a>.<\/p>\n<p>One way or another, the core idea is that nobody sees much harm in unpacking the archive, so many people click without giving it a second thought.<\/p>\n<h3>What happens when the bug is exploited<\/h3>\n<p>The malware\u00a0payloads can be anything: remote access <a target=\"_blank\" href=\"https:\/\/ti.360.net\/blog\/articles\/apt-c-27-(goldmouse):-suspected-target-attack-against-the-middle-east-with-winrar-exploit-en\/\" rel=\"noopener noreferrer nofollow\">tools<\/a> of different kinds, enabling hijackers to capture your screen and upload or download files to or from your device, or a banking Trojan, or ransomware, or any other of the innumerable malware species out there.<\/p>\n<p>The most recent example of <a target=\"_blank\" href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/jneca-ransomware-spread-by-winrar-ace-exploit\/\" rel=\"noopener noreferrer nofollow\">malware spreading using the WinRAR vulnerability<\/a> is JNEC.a, new ransomware\u00a0that locks all of the files on an infected device. At the moment, the cybercriminals are asking for a relatively modest ransom to decrypt your data: 0.05 bitcoins (about $200).<\/p>\n<h3>How to protect yourself against malware spreading through WinRAR bug<\/h3>\n<ul>\n<li>Update your WinRAR right away. Unfortunately, there\u2019s no automatic update, so you have to do it manually. Go to the official <a target=\"_blank\" href=\"https:\/\/www.win-rar.com\/download.html\" rel=\"noopener noreferrer nofollow\">WinRAR website<\/a>, download version 5.70 or a more recent one, and install it.<\/li>\n<li>To stay on the safe side, do not open any archives you receive from unknown senders.<\/li>\n<li>Use a reliable security solution such as <a href=\"https:\/\/www.kaspersky.com\/internet-security?icid=gl_kdailyplacehold_acq_ona_smm__onl_b2c_kasperskydaily_wpplaceholder____kismd___\" target=\"_blank\" rel=\"noopener nofollow\">Kaspersky Internet Security<\/a> to immunize your system against potential attack.<\/li>\n<\/ul>\n<input type=\"hidden\" class=\"category_for_banner\" value=\"kis-trial-cyberattacks\">\n","protected":false},"excerpt":{"rendered":"<p>A bug in WinRAR allows malefactors to gain full control over your device. All they need you to do is unpack a rigged RAR file.<\/p>\n","protected":false},"author":2508,"featured_media":26232,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[5,2683],"tags":[1103,36,76,268,113,1277],"class_list":{"0":"post-26231","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-news","8":"category-threats","9":"tag-bug","10":"tag-malware-2","11":"tag-phishing","12":"tag-vulnerabilities","13":"tag-windows","14":"tag-winrar"},"hreflang":[{"hreflang":"x-default","url":"https:\/\/www.kaspersky.com\/blog\/update-winrar-now\/26231\/"},{"hreflang":"en-in","url":"https:\/\/www.kaspersky.co.in\/blog\/update-winrar-now\/15525\/"},{"hreflang":"en-ae","url":"https:\/\/me-en.kaspersky.com\/blog\/update-winrar-now\/13072\/"},{"hreflang":"en-us","url":"https:\/\/usa.kaspersky.com\/blog\/update-winrar-now\/17450\/"},{"hreflang":"en-gb","url":"https:\/\/www.kaspersky.co.uk\/blog\/update-winrar-now\/15599\/"},{"hreflang":"es-mx","url":"https:\/\/latam.kaspersky.com\/blog\/update-winrar-now\/14239\/"},{"hreflang":"es","url":"https:\/\/www.kaspersky.es\/blog\/update-winrar-now\/18107\/"},{"hreflang":"it","url":"https:\/\/www.kaspersky.it\/blog\/update-winrar-now\/17099\/"},{"hreflang":"ru","url":"https:\/\/www.kaspersky.ru\/blog\/update-winrar-now\/22534\/"},{"hreflang":"tr","url":"https:\/\/www.kaspersky.com.tr\/blog\/update-winrar-now\/5826\/"},{"hreflang":"fr","url":"https:\/\/www.kaspersky.fr\/blog\/update-winrar-now\/11556\/"},{"hreflang":"pt-br","url":"https:\/\/www.kaspersky.com.br\/blog\/update-winrar-now\/11613\/"},{"hreflang":"pl","url":"https:\/\/plblog.kaspersky.com\/update-winrar-now\/10556\/"},{"hreflang":"de","url":"https:\/\/www.kaspersky.de\/blog\/update-winrar-now\/18851\/"},{"hreflang":"ja","url":"https:\/\/blog.kaspersky.co.jp\/update-winrar-now\/22860\/"},{"hreflang":"ru-kz","url":"https:\/\/blog.kaspersky.kz\/update-winrar-now\/18191\/"},{"hreflang":"en-au","url":"https:\/\/www.kaspersky.com.au\/blog\/update-winrar-now\/22380\/"},{"hreflang":"en-za","url":"https:\/\/www.kaspersky.co.za\/blog\/update-winrar-now\/22316\/"}],"acf":[],"banners":"","maintag":{"url":"https:\/\/www.kaspersky.com\/blog\/tag\/windows\/","name":"Windows"},"_links":{"self":[{"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts\/26231","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/users\/2508"}],"replies":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/comments?post=26231"}],"version-history":[{"count":5,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts\/26231\/revisions"}],"predecessor-version":[{"id":29490,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts\/26231\/revisions\/29490"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/media\/26232"}],"wp:attachment":[{"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/media?parent=26231"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/categories?post=26231"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/tags?post=26231"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}