Russia and China-backed hackers are exploiting WinRAR zero-day bug

Wilshire@lemmy.world to Technology@lemmy.world – 457 points –
Russia and China-backed hackers are exploiting WinRAR zero-day bug | TechCrunch
techcrunch.com
125

Blows my mind that anyone still uses WinRAR when 7zip exists.

What should blow your mind is that it's 2023 and you still need a separate program to extract compressed files on windows. 😂 Good thing they're adding native support for it in windows 11. FINALLY.

Yeah, it just sucks.

Same for Macs. They technically support zipping and unzipping, they're just bad at it. It's so stupid.

How so? I’ve always found finder did a good job.

There's a maximum file size, I forget what it is. And it also can't handle zips in multiple pieces.

Finder is an abortion, there is not a single thing it does well

An abortion you can't even get rid of! Its icon is stuck the dock forever, even if you use something better like Forklift. The whole mac GUI is just shit.

When did windows have native rar support?

Since Win 11 23H2. It's not out officially yet but the insider/RC builds have had it for a while now.

You do on Linux as well, it's just installed by default.

For my personal use, Linux has every single thing I need right out of the box. That's why it's my main OS.

If you don't mind me asking, what's your distro and why did you settle on that particular one? I'm in the process of trying out different distros in anticipation of eventually moving all my stuff over and getting out of Windows completely, and that was really high praise, lol.

So if you have a moment I'd really appreciate hearing about why you picked the distro you did, because being front loaded is one of the things I'm low key looking for: I don't know Linux well enough to know what I might need out of the box, so the more that's already on it the better (no shortage of drive space, fortunately). If it appeals I'll load it up on a LiveUSB and test drive it myself. Thanks!

I don't mind. I have two machines that run Linux and one that runs windows. Main desktop I built last month runs endeavourOS. A 13" laptop that runs Ubuntu. A 15" laptop that runs windows. I like arch because it is always on the latest software. Some people like to be on the cutting edge and others don't. I'm the former. But I didn't want to run vanilla arch because I'm too lazy for maintenance and building my distro from ground up. EndeavourOS is arch with an installer and extra repos. It gives you a solid distro out of the box that you don't need to do much work on after it's installed. It just works. Never had an issue. I just update twice or once a week and I'm good to go. I have it set up with btrfs and snapshots in case it does break.

Ubuntu on the laptop because I like Ubuntu on little machines. Every single thing works out of the box. Ubuntu is very neat. A lot of people hate on it and on snaps, but I honestly don't care. I use what works for me. Anything Linux is good to me and they vary in how good they are. Also, Ubuntu is kind of nostalgic to me. It was the first thing I knew about Linux back in 2013.

But here is the thing, I told you what I use, but it may not work for you. That's why I love Linux. There is a distro for everyone. You can try what I use and see if you like them, if not keep distro hopping until you settle on something you love like I did. I personally wouldn't listen to any suggestions on here, Reddit or anywhere on what distro to use (that's just me btw). I distro hopped for almost two years until I settled on what I have now. Hope this helps.

Thank you for your response, this is exactly the info I was looking for. It may not work for me, but knowing WHY someone else loves it tells me a lot about it. I listen to every suggestion, but I first tried Linux back in the 90s: I'm not really swayed by emotive pleas because I've already heard them all. (The first time I ever heard that joke about if OSs were airlines and Unix/Linux would be the one where people brought the parts and assembled it on the runway while fighting the entire time was around that same period; it has only ever gotten to be even more true over the ages, lol.)

At this point I have over a dozen LiveUSB or install sticks and I'm just rotating through them, spending a week or two on the distros I like. I'm on Zorin OS right now, which is on the list because it claims to have great Windows app support out of the box, and it's great but I still need to test that part (and I'm procrastinating because it's a major pain in the ass but I will eventually).

EndeavourOS is one of the ones I keep hearing about, and it's very high on the list at distrowatch.com, but I don't really hear about it from the folks that use it so this is exactly what I was looking for. I really appreciate you taking the time to spell out what you're using on what hardware and why, it cuts out a lot of the chaff that inevitably flies around distro choices. "Yeah, I know you like [____], but WHY does it work for you?" is a lot more helpful, and you gave me that. EndeavourOS is absolutely on my list now, and knowing that it comes preloaded with everything I might ever need helps a lot. Thank you again.

Of course. Good luck to ya. Make sure to post your questions here on this community if you run into any issues. I've noticed that the Linux "sub"/community over here on Lemmy is way more relaxed than on Reddit. You can ask questions, you can post random shit and no one will yell at you. Mods can sometimes be a pain in the ass on reddit.

If you're new, Ubuntu (or one of its variants, like Xubuntu or Kubuntu) or Linux Mint are great "safe" options. The only thing to consider with Mint is that there is only an LTS release so you will end up with older versions of some programs. I've been using Linux as my primary OS for 17 years but I will still throw Xubuntu on a laptop if I just want to get something up and running quickly - other than having some extra packages installed out of the box there's nothing "wrong" with it.

That said I use openSUSE Tumbleweed as my daily driver. I like the rolling release and cutting edge packages, plus I like that YaST allows me to install the system exactly the way I want - picking and choosing individual packages.

Thank you so much for your response. I have tried Mint; it ran perfectly out of the box with zero issues on a 13 year old laptop; I just didn't care for the Cinnamon DE so I have it on my list to try again with a different DE. Snaps aren't too much of an issue because it supports other repositories.

I've also tried OpenSUSE Leap but not Tumbleweed; I think I had to do the full install (no LiveUSB) but as an OS it was great. I ran it for a week but had some video issues with it, weird horizontal lines that go across the screen for a few seconds at boot, shut down, and login. Not a deal killer but I've set it aside for right now while I try other distros. (One thing I love so far about the Arch distros is that the online knowledge base is truly easy for someone with basic tech knowledge but no Linux knowledge to find what they need.) Really appreciate you taking the time to respond, thank you!

8 more...

And often, you need two! I use both gzip and tar all the time

Same with Mac OS, it’s such a fucking no brainer and it’s not hard to impl

8 more...

they’re adding native support for it in windows 11

What could possibly go wrong.

Windows' built in unzipping tool has really messed up my system before by uncompressing files wrong in subtle ways. I'll always prefer to use a program made by a third party whose livelihood depends on the quality of their software over some value-add baked in junk.

I'm willing to bet a big part of that are all the antitrust lawsuits they got for internet explorer and windows media player back in the day and just not wanting to open that box as it comes to rarlab.
.zip support they've had for well over two decades though.

9 more...

WinRAR was good in ancient times when it was the only zip program available. Even in the Windows XP era there were better things to use if you knew about them. I doubt 7zip was really that usable in the early 2000s but it eventually got good and nowadays 7zip is so good that of you aren't using it, you're doing it wrong.

Winrar in ancient times? Lol. People have been arching for a long time before that. Unix, amiga, apple, pc... that is a funny sentence.

Don't remember PKARK, ARC, and PKWARE? Zip became popular after the battle with SEA.

I believe Winrar became popular because it was easier to use with multi volume archives. Which conveniently worked well with parity files, which all worked great for distributing on usenet.

Well it would blow your mind to know that many people just use whatever they know that does the job

There is a certain sense of old friend that you know by heart, I've downloaded so much things where the last step was to pass it by WinRAR, but yeah I should change when there are proofs like that

FUCK WINRAR!

it's so stupid and amazing this recent celebration of people that are proud to have paid for it.

It was never a good solution really..

It just worked for what it was for a time... Because it was better than WinZip or pkzip.

7-zip has been amazing for years..

Better OS support would be cool too but it's so unnecessary thanks to 7zip.

FUCK WINRAR!

People on Lemmy sometimes get really angry at the dumbest things.

You don't like Winrar, that's your right, chill dude.

WinRAR is shit and I have no need to chill.

But guess what, thinking and expressing that you think my opinion is dumb is your right so carry on otherwise.

WinRAR was great for the time and their policies on paying for the program were extremely generous. Time just overtook it.

It's essentially just shareware.

More specifically, it's nagware which wasn't particularly uncommon for the time WinRAR was introduced so I don't know that it's particularly generous really when one considers all the other nagware that came out in the late 90s.

It's just one of many different licensing strategies.

In this case it seems to have paid off for the developer as it appears to have resulted in a great deal of fondness and goodwill among a certain portion of the user base.

It was never great.

Their "generous" pay if you want to remove this obnoxious message prompt aside...

It was temporarily useful until better alternatives arose... Which took virtually no time.

Back in the day WIndows didn't even have the capability to deal with ZIPs natively. Even if its time was brief (which I honestly don't remember, I think that it was useful for years, almost up to Vista's time) it was useful.

And I do think it generous that this paid software just let you use it after clicking a button with no time limit. Time gave us better options, but I think a lot of people look at WinRAR harsher than it deserves.

Most people already had WinZip for zip files before Windows had built in support and most people didn't ever really even deal with rar files.

This revisionist history is so wild I can only assume you are 16 years old and freshly playing on your first computer that you dont need to share

Lol... You people and your condescension is what's fucking wild.

As if only a child could disagree with your stupid fucking opinions.

Get over yourself.

Only a child wouldnt have lived through the history, and so doesnt know it.

You're a fucking idiot.

People have different opinions.

I am 50 fucking years old and I'd be really surprised if you're older considering the immature shit you're spouting at me.

It was temporarily useful until better alternatives arose... Which took virtually no time.

This is just an inaccurate timeline of events, not a difference of opinion.

Im very sorry to hear you spent 40 years of your life in a coma, but Im glad youre up and walking now.

7z recently also had an exploit. It's not magically safer.

RAR compresses significantly faster than 7z (in relation to the compression ratio of course).

RAR has recovery records, 7z doesn't. RAR4 even had cryptographic signatures included. But RAR5 dropped that.

7z is nice, but it's not objectively better than RAR on every account.

Your can create recovery records, par2, for zip archives

It just worked for what it was for a time… Because it was better than WinZip or pkzip.

Yes this is why it is loved as a piece of software history.

I get you probably were a twinkle in your dad's eye in those days, but that doesn't mean people who were alive then should care less.

Dude... I'm 50 years old and have worked in the technology industry since 1997.

Which should be pretty obvious considering I mentioned fucking pkzip which was a DOS utility.

Give me a fucking break with the condescension.

Then, frankly, it's weird that you said anything because you should know your history and, at 50, have enough of a grasp of how humanity functions to see why people are nostalgic.

2 more...
2 more...
2 more...
2 more...

We hate WinRAR now?

Not hate but we graduate to 7zip.

Isnt the FOSS thingie all the hype around lemmy? Feel like every discussion tends to drift towards FOSS topics (ironic, I know) and if an app with proprietary modules will be hated to hell and back.

Oh, I've somehow never seen anyone express that 7zip is FOSS; I didn't realize that. This should be the first thing anyone points out about it.

I just feel like that people who are still opening RAR files are technically savvy enough to have moved on from WinRAR

Edit: and the people who would still use it aren’t really opening archives anymore so I don’t know who this is affecting. Maybe they have corporate contracts.

WinRAR had a great gui and it integrates much better (imho) into windows than 7zip, only thing 7zip has going for it is it's free.

If we are talking command line, rar is free (inb4 Unix guys butt in)

The only thing I missed switching to 7zip was the UX. 7zip is a bit weird at first, but then you find out that it will extract lots of installers. So now you can just get the wifi driver and not the bloatware that comes along with it, and it's all good.

7zip integrates very nicely into Explorer (so you can right click a file or folder and compress straight from there). I admit the main GUI of 7zip looks ancient but I never needed it.

doesn't WinRAR do certain things that 7zip doesn't?

I can't think of what 7zip lacks, but I know it does lack some features

The reason WinRAR was useful to me allllllll those years ago was for one thing and one thing only: You could split an archive into chunks. So mostly I found that it was good for getting my warez in 1.44MB chunks.

Anon: hey Krudler, do you have a cracked copy of GTA3

Krudler: say no more, friend

Sends 350 floppy disks with the cracked game

Yes. That splitting files was especially useful because emails used to have attachment size limits.

No no no no

It was primarily used to post to USENET.

Back in the day, every byte of data was precious and bandwidth was insanely limited, nobody would ever email an attachment for that.

Due to some of the technical details about how email works, that would end up just bloating the file size and it would be the literally most inefficient way possible to send large blobs of data.

Afaik, the only thing 7Zip lacks in comparison to WinRAR is the ability to create rar files, and that's only because the format is proprietary.

this is true I actually needed to get winrar to install a free game I acquired lately 7z would not open it properly for some reason

6 more...

Why not? I prefer it over 7-Zip because it has built-in parity both in the archive itself and as separate files. You can achieve the latter with 7-Zip using PAR, but it's just more convenient to have it built-in for both parity creation and recovery.

I also feel like it's consuming a lot less RAM while compressing at similar speeds and achieving similar, if not sometimes better (RAR5), results.

Just because it had a zero-day bug that has already been fixed doesn't mean it's bad software. I wouldn't be surprised if zero-days came to light in other archival software. 7-Zip isn't magically immune to this.

I don't get why someone would prefer rar over zip and 7z.
Even tar.gz and all their flavors are more common.

Yeah, well technically .cab is more common than tar.gz but that doesn't mean I'd start using it.

I personally use RAR because I think it's a better format than ZIP, but I use ZIP when I have to share the archive with anyone.

WinRAR also has clever password and encryption features. (Set short master password, quickly encrypt/decrypt any saved very long passwords.) Integration is great. Updates are regular. I only wish the UI would be updated a bit (more than just icon packs, dark mode).

There's the occasional RAR archive 7-Zip doesn't open for me, but WinRAR does. 🤷🏻

17 more...

7zip exists and is free.

7zip will unpack rar files? I've used it for years and never knew.

It'll unpack everything

Packing / unpacking: 7z, XZ, BZIP2, GZIP, TAR, ZIP and WIM Unpacking only: APFS, AR, ARJ, CAB, CHM, CPIO, CramFS, DMG, EXT, FAT, GPT, HFS, IHEX, ISO, LZH, LZMA, MBR, MSI, NSIS, NTFS, QCOW2, RAR, RPM, SquashFS, UDF, UEFI, VDI, VHD, VHDX, VMDK, XAR and Z.

https://www.7-zip.org/

Will it unpack my bags from the weekend? Cos it's Friday now and I still can't be bothered

If you give it access to robot arms it will.

What about the emotional baggage I lug around on a daily basis?

You may have problems unpacking RAR of latest format versions with 7zip. It's been some time since I encountered that.

Yea. It just can’t pack files into RaR.

I can't find any reason why someone would still use rar in 2023. When I see anyone using it, it means to me they're as technologically literate as my grandpa.

So pretty literate compared to most older people.

Fuck WinRAR. It's for normie NPCs. 7Zip is FOSS, and everybody should be using it instead.

7zip's Linux port (p7zip) was lagging back in functionality last I heard, and also was abandoned then, don't know how it is now.

5 more...

Better yet stop using Windows

I'm a .NET dev, I wish lmao

I'd say "well .NET is cross platform" but knowing the average company on .NET it's probably version 3.5 and running off a windows 95 server that hisses whenever someone gets too close to it.

1 more...

Tbh I quite like developing .net on my Mac. I do away with VS and just use vscode and command line. It feels nice

I used to use Mac with rider on my last job, and it worked nicely! Sadly it's not really an option working with legacy stuff

1 more...

Better yet

Not feasible for the vast majority of users. It's still not mature. Dunno when it'll be if ever.

2 more...

Wow, really shilling for Russian software man, that's low, certainly the Russians have no insights to 7zip.

You can read and build the source code yourself if you're really worried what some Russian FOSS contributors are up to, but I can assure you it's going to be a lot less sus that whatever a proprietary application can do without any ability to audit and check the code.

7 more...

Who the hell hurts winRAR? That's like punching Dolly Parton.

"Group-IB said the flaw was exploited as a zero-day — since the developer had zero time to fix the bug before it was exploited — as far back as April to compromise the devices of at least 130 traders."

We're all to blame for not registering

This is the best summary I could come up with:


The WinRAR vulnerability, first discovered by cybersecurity company Group-IB earlier this year and tracked as CVE-2023-38831, allows attackers to hide malicious scripts in archive files that masquerade as seemingly innocuous images or text documents.

In research shared with TechCrunch ahead of its publication, TAG says it has observed multiple campaigns exploiting the WinRAR zero-day bug, which it has tied to state-backed hacking groups with links to Russia and China.

One of these groups includes a Russian military intelligence unit dubbed Sandworm, which is known for destructive cyberattacks, like the NotPetya ransomware attack it launched in 2017 that primarily hit computer systems in Ukraine and disrupted the country’s power grid.

Separately, TAG says it observed another notorious Russia-backed hacking group, tracked as APT28 and commonly known as Fancy Bear, using the WinRAR zero-day to target users in Ukraine under the guise of an email campaign impersonating the Razumkov Centre, a public policy think tank in the country.

Google’s findings follow an earlier discovery by threat intelligence company Cluster25, which said last week that it had also observed Russian hackers exploiting the WinRAR vulnerability as a phishing campaign designed to harvest credentials from compromised systems.

Google added that its researchers found evidence that the China-backed hacking group, known as APT40, which the U.S. government has previously linked to China’s Ministry of State Security, also abused the WinRAR zero-day flaw as part of a phishing campaign targeting users based in Papua New Guinea.


The original article contains 490 words, the summary contains 239 words. Saved 51%. I'm a bot and I'm open source!

I read "dubbed Sandworm" but my brain always displays darude Sandstorm in my mind.

Stop Using Windows And MacOS use GNU/Linux instead -> Problem Solved

Yeah problem solved, except you have to deal with Linux problems instead

There are no problems on GNU/Linux only new areas of ignorance coming to your awareness. These are really opportuinities to learn. What you call problems is really some sort of ignorance of the underlying systems. Filling in the blind spot usually resolves the issue. You becoming aware of this is a great opportunity for this to self-correct. Thus you don't have problems on GNU/linux instead you have growing opportunities. And boy oh boy are there lots of them 😃