"Russian APT Groups Exploit WinRAR Vulnerability to Target Embassies"

1 min read
Source: BleepingComputer
"Russian APT Groups Exploit WinRAR Vulnerability to Target Embassies"
Photo: BleepingComputer
TL;DR Summary

A state-sponsored Russian hacker group known as APT29, or various other names including Cozy Bear and SolarStorm, has been exploiting the CVE-2023-38831 vulnerability in WinRAR to target embassy entities. They have been using a BMW car sale lure to deliver a malicious ZIP archive that runs a script in the background, allowing them to download and execute a payload. APT29 has also been utilizing Ngrok's new feature of free static domains to hide their communication with compromised systems. The Ukrainian National Security and Defense Council (NDSC) has provided indicators of compromise (IoCs) for detection.

Share this article

Reading Insights

Total Reads

0

Unique Readers

1

Time Saved

2 min

vs 3 min read

Condensed

82%

51894 words

Want the full story? Read the original article

Read on BleepingComputer