Tag

Government Backed Hackers

All articles tagged with #government backed hackers

cybersecurity2 years ago

WinRAR Security Vulnerability Exploited by Russian and Chinese Hackers

Government-backed hackers from Russia and China have been exploiting a known vulnerability in outdated versions of WinRAR, a popular compression tool used by over 500 million users. The vulnerability allows hackers to spoof file extensions and hide malicious scripts within seemingly harmless files. Google's Threat Analysis Group (TAG) has identified hacker groups, including the Russian Armed Forces group "Sandworm" and China's "APT 40," exploiting this vulnerability in targeted campaigns. Google urges users to update their WinRAR software to the latest version to protect against these attacks and emphasizes the importance of regular software updates for cybersecurity.

cybersecurity2 years ago

WinRAR's Security Vulnerability Exploited by Russian and Chinese Hackers

Google security researchers have discovered evidence that government-backed hackers linked to Russia and China are exploiting a previously patched vulnerability in WinRAR, a popular archiving tool for Windows. The vulnerability, known as CVE-2023-38831, allows attackers to hide malicious scripts in archive files. Despite an updated version of WinRAR being released, multiple state-backed hacking groups, including Sandworm and Fancy Bear from Russia, and APT40 from China, have been observed exploiting the flaw in targeted phishing campaigns. The ongoing exploitation of this bug highlights the effectiveness of known vulnerability exploits due to slow patching rates.