#winrar — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #winrar, aggregated by home.social.
-
Hits Safe Mode: Ransomware Rebooting Around EDR
An Akira ransomware affiliate gained initial access through an exposed SonicWall VPN without multi-factor authentication via credential spraying. After compromising the domain controller, the attacker performed Active Directory enumeration, collected and exfiltrated data using WinRAR and s5cmd to cloud storage. The affiliate employed a novel evasion technique by rebooting the victim host into Safe Mode with Networking to disable EDR and antivirus protection. AnyDesk was installed as a persistent remote access mechanism. However, the Safe Mode environment caused the ransomware to fail due to out-of-virtual-memory errors, preventing encryption. Despite the encryption failure, the attacker had already exfiltrated credentials and file shares, enabling extortion through data leak threats. This marks the first observed instance of Akira affiliates using Safe Mode boot as an anti-EDR technique.
Pulse ID: 6a7ca262c4921e41ead16a57
Pulse Link: https://otx.alienvault.com/pulse/6a7ca262c4921e41ead16a57
Pulse Author: AlienVault
Created: 2026-08-12 16:42:10Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Akira #AnyDesk #Cloud #CyberSecurity #DomainController #EDR #Encryption #Extortion #InfoSec #OTX #OpenThreatExchange #RAT #RansomWare #Troll #VPN #WinRAR #bot #AlienVault
-
Hits Safe Mode: Ransomware Rebooting Around EDR
An Akira ransomware affiliate gained initial access through an exposed SonicWall VPN without multi-factor authentication via credential spraying. After compromising the domain controller, the attacker performed Active Directory enumeration, collected and exfiltrated data using WinRAR and s5cmd to cloud storage. The affiliate employed a novel evasion technique by rebooting the victim host into Safe Mode with Networking to disable EDR and antivirus protection. AnyDesk was installed as a persistent remote access mechanism. However, the Safe Mode environment caused the ransomware to fail due to out-of-virtual-memory errors, preventing encryption. Despite the encryption failure, the attacker had already exfiltrated credentials and file shares, enabling extortion through data leak threats. This marks the first observed instance of Akira affiliates using Safe Mode boot as an anti-EDR technique.
Pulse ID: 6a7ca262c4921e41ead16a57
Pulse Link: https://otx.alienvault.com/pulse/6a7ca262c4921e41ead16a57
Pulse Author: AlienVault
Created: 2026-08-12 16:42:10Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Akira #AnyDesk #Cloud #CyberSecurity #DomainController #EDR #Encryption #Extortion #InfoSec #OTX #OpenThreatExchange #RAT #RansomWare #Troll #VPN #WinRAR #bot #AlienVault
-
Analysis of a Modular Cyber Espionage Framework
Security researchers have uncovered a sophisticated cyber espionage operation deploying two previously undocumented malware families, OctLurk and SilkLurk, targeting government and public-sector organizations across Central Asia and the Middle East. Both modular backdoors utilize victim-specific decryption mechanisms, extensive obfuscation, and in-memory execution to evade detection. The malware enables credential theft, remote access, network reconnaissance, and plugin-based expansion. Operations began in January 2025, affecting entities in Afghanistan, Kazakhstan, Kyrgyzstan, Syria, Tajikistan, and Uzbekistan. Victims include government offices, foreign affairs ministries, law enforcement agencies, healthcare providers, logistics organizations, research institutions, urban planning facilities, and educational establishments. Attackers deployed additional tools including Impacket's SecretsDump, Browser Password Decryptor, Pandora RC, Fscan, WinRAR, 7-Zip, and PlugX. A companion utility, LurkProxy, proxies a
Pulse ID: 6a75b204c9420179df545451
Pulse Link: https://otx.alienvault.com/pulse/6a75b204c9420179df545451
Pulse Author: AlienVault
Created: 2026-08-07 10:23:00Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Afghanistan #Asia #BackDoor #Browser #CentralAsia #CyberSecurity #Education #Espionage #Government #Healthcare #ICS #InfoSec #Kazakhstan #LawEnforcement #Malware #MiddleEast #OTX #Office #OpenThreatExchange #Password #PlugX #Proxy #RAT #RCE #SMS #Syria #WinRAR #Word #ZIP #bot #AlienVault
-
Analysis of a Modular Cyber Espionage Framework
Security researchers have uncovered a sophisticated cyber espionage operation deploying two previously undocumented malware families, OctLurk and SilkLurk, targeting government and public-sector organizations across Central Asia and the Middle East. Both modular backdoors utilize victim-specific decryption mechanisms, extensive obfuscation, and in-memory execution to evade detection. The malware enables credential theft, remote access, network reconnaissance, and plugin-based expansion. Operations began in January 2025, affecting entities in Afghanistan, Kazakhstan, Kyrgyzstan, Syria, Tajikistan, and Uzbekistan. Victims include government offices, foreign affairs ministries, law enforcement agencies, healthcare providers, logistics organizations, research institutions, urban planning facilities, and educational establishments. Attackers deployed additional tools including Impacket's SecretsDump, Browser Password Decryptor, Pandora RC, Fscan, WinRAR, 7-Zip, and PlugX. A companion utility, LurkProxy, proxies a
Pulse ID: 6a75b204c9420179df545451
Pulse Link: https://otx.alienvault.com/pulse/6a75b204c9420179df545451
Pulse Author: AlienVault
Created: 2026-08-07 10:23:00Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Afghanistan #Asia #BackDoor #Browser #CentralAsia #CyberSecurity #Education #Espionage #Government #Healthcare #ICS #InfoSec #Kazakhstan #LawEnforcement #Malware #MiddleEast #OTX #Office #OpenThreatExchange #Password #PlugX #Proxy #RAT #RCE #SMS #Syria #WinRAR #Word #ZIP #bot #AlienVault
-
Looks like BetterZip for Mac received another big update with new features and bug fixes. I like this!
Link: https://macitbetter.com
-
Looks like BetterZip for Mac received another big update with new features and bug fixes. I like this!
Link: https://macitbetter.com
-
WinRAR 7.23 foi lançado com um agradecimento irónico aos utilizadores que suportaram o projeto. O compactador de ficheiros agradeceu a todos que abriram a carteira para suportar o projeto. 📦
🔗 https://tugatech.com.pt/t86872-winrar-7-23-chega-com-agradecimento-ironico-a-quem-comprou-a-licenca
-
WinRAR 7.23 foi lançado com um agradecimento irónico aos utilizadores que suportaram o projeto. O compactador de ficheiros agradeceu a todos que abriram a carteira para suportar o projeto. 📦
🔗 https://tugatech.com.pt/t86872-winrar-7-23-chega-com-agradecimento-ironico-a-quem-comprou-a-licenca
-
「WinRAR 7.23」が公開 ~ヒープオーバーフローなど2件の脆弱性に対処/7zファイルの展開モジュールは「7-Zip 26.02」相当に
https://forest.watch.impress.co.jp/docs/news/2121981.html#forest_watch_impress #WinRAR #RAR #セキュリティ #脆弱性 #Windows #圧縮_解凍 #解凍 #圧縮
-
Nova versão WinRAR 7.23 corrige falhas críticas de segurança no Windows. O descompactador de ficheiros WinRAR lançou uma atualização com o objetivo de resolver problemas de segurança graves.
-
Nova versão WinRAR 7.23 corrige falhas críticas de segurança no Windows. O descompactador de ficheiros WinRAR lançou uma atualização com o objetivo de resolver problemas de segurança graves.
-
Version 7.23 de WinRAR, popular aplicación de compresión y descompresión de archivos para Windows, macOS, Linux y Android: https://www.dekazeta.net/foro/files/file/4893-winrar/
-
Version 7.23 de WinRAR, popular aplicación de compresión y descompresión de archivos para Windows, macOS, Linux y Android: https://www.dekazeta.net/foro/files/file/4893-winrar/
-
-
-
RE: https://velocipederider.com/@archivetoolstracker/116841303345760390
This RAR has security fixes, just like the 7-Zip update a few days back. Update!
-
RE: https://velocipederider.com/@archivetoolstracker/116841303345760390
This RAR has security fixes, just like the 7-Zip update a few days back. Update!
-
🚨 Google has linked Turla to a new .NET backdoor.
STOCKSTAY was used in espionage campaigns targeting #Ukraine government and military organizations.
It overlaps with Kazuar and reached targets through phishing, RDP files, MSI installers, and #WinRAR CVE-2025-8088 lures.
See the full attack details 🠖 https://thehackernews.com/2026/06/google-details-turlas-new-stockstay.html
-
-
-
A WinRAR está a celebrar a compra de licenças pelos seus clientes com posts na rede social X. A marca aproveitou para relembrar os tempos em que os utilizadores tentavam extrair ficheiros durante o período de teste 📦
-
A WinRAR está a celebrar a compra de licenças pelos seus clientes com posts na rede social X. A marca aproveitou para relembrar os tempos em que os utilizadores tentavam extrair ficheiros durante o período de teste 📦
-
Gamaredon sfrutta CVE-2025-8088 in WinRAR per distribuire GammaWorm e GammaSteel contro l’Ucraina
Sekoia documenta una campagna di gennaio 2026 del gruppo APT russo Gamaredon: sfruttando CVE-2025-8088 in WinRAR, gli operatori dell'FSB distribuiscono GammaPhish, GammaLoad, GammaWorm e GammaSteel contro target governativi e militari ucraini. La catena usa Telegram come dead drop resolver per il C2 e NTFS Alternate Data Streams per l'evasione, con esfiltrazione finale verso AWS S3. -
Gamaredon sfrutta CVE-2025-8088 in WinRAR per distribuire GammaWorm e GammaSteel contro l’Ucraina
Sekoia documenta una campagna di gennaio 2026 del gruppo APT russo Gamaredon: sfruttando CVE-2025-8088 in WinRAR, gli operatori dell'FSB distribuiscono GammaPhish, GammaLoad, GammaWorm e GammaSteel contro target governativi e militari ucraini. La catena usa Telegram come dead drop resolver per il C2 e NTFS Alternate Data Streams per l'evasione, con esfiltrazione finale verso AWS S3. -
Gamaredon Exploits WinRAR Flaw to Deliver GammaWorm, GammaSteel Malware
Cyber attackers have cleverly exploited a WinRAR flaw to unleash a potent malware duo, GammaWorm and GammaSteel, with the goal of taking control of infected systems and executing malicious scripts. This sneaky tactic, spotted by French cybersecurity firm Sekoia, allows hackers to fingerprint host systems, manipulate network settings, and…
-
FSB-Linked Worm Exploits Windows Flaw to Evade Detection
Cyber attackers have cleverly exploited a known Windows flaw, CVE-2025-8088, to sneak a malicious payload into victims' systems, allowing them to gain access and lay the groundwork for further attacks. This stealthy move was uncovered by Sekoia, which tracked the initial access stage as GammaPhish.
-
Storing my GOG.com gaming library on my local harddisk drive. Oh, wow... WinRAR sure eats up these CPU cores for dinner. Flawless multi-threading! 😎
#WinRAR #CPU #Processor #AMD #Ryzen #Windows #GOG #Preservation #Archiving
-
Storing my GOG.com gaming library on my local harddisk drive. Oh, wow... WinRAR sure eats up these CPU cores for dinner. Flawless multi-threading! 😎
#WinRAR #CPU #Processor #AMD #Ryzen #Windows #GOG #Preservation #Archiving
-
#WinRAR 7.22 has been released (#RAR / #ZIP / #ZIPX / #7Zip / #7z / #GZip / #zstd / #Zstandard / #FileArchiver / #DataCompression / #DarkMode) https://rarlab.com/
-
#WinRAR 7.22 has been released (#RAR / #ZIP / #ZIPX / #7Zip / #7z / #GZip / #zstd / #Zstandard / #FileArchiver / #DataCompression / #DarkMode) https://rarlab.com/
-
New XWorm 7.1 and Remcos RAT campaigns are abusing trusted #Windows utilities and memory-based execution to evade detection, giving attackers remote access to infected systems. The campaign also exploits a #WinRAR vulnerability to gain initial access.
Read: https://hackread.com/xworm-7-1-remcos-rat-windows-tools-evade-detection/
-
Nowa kampania cyberszpiegowska. Grupa Amaranth-Dragon atakuje strategiczne cele przy użyciu luki w WinRAR (CVE-2025-8088)
Nie tak dawno, bo w ubiegłym roku została wykryta podatność w dobrze znanym WinRAR o czym pisaliśmy tutaj. I choć mogłoby się wydawać, że wraz z wydaniem aktualizacji problem został rozwiązany, to rzeczywistość pokazała, że nie do końca tak jest. Zwłaszcza, gdy do gry wkraczają grupy APT. W najnowszym wpisie...
-
#Peazip sigue mejorando. Es un señor programón para trabajar con archivos comprimidos y cifrados. Si seguís usando #WinRAR notaréis mucha diferencia. Si ya veníais de usar #7zip quizá no notéis inmediatamente muchas funciones adicionales (que las hay) pero sí una mayor facilidad de uso e interfaz más agradable.
-
WinRAR 7.20 chegou: Atualização traz mais velocidade e controlo total aos teus ficheiros
🔗 https://tugatech.com.pt/t77755-winrar-7-20-chegou-atualizacao-traz-mais-velocidade-e-controlo-total-aos-teus-ficheiros