Beware of Fake WinRAR Website That Delivers Malware with WinRAR Installer
ID: cac70bca-b4e5-5672-9f92-f6c566b08a61
STIX ID: report--cac70bca-b4e5-5672-9f92-f6c566b08a61
Feed Name: cybersecurityNews.com
A malicious campaign is distributing a trojanized WinRAR installer (winrar-x64-713scp.zip) via fake download domains (e.g., winrar-tw.com, winrar-x64.com, winrar-zip.com) to deliver the Winzipper backdoor. The multi-stage payload is UPX-packed and contains a password-protected setup.hta that is unpacked into memory to evade detection, spawning nimasila360.exe and enabling data theft, remote access, and secondary payloads; Malwarebytes identified and blocked the domains and warns users to obtain WinRAR only from official sources.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
