logo

Fake WinRAR downloads hide malware behind a real installer

ID: dfc88115-9fa4-5a73-84e3-24ba526483be

STIX ID: report--dfc88115-9fa4-5a73-84e3-24ba526483be

Feed Name: Malwarebytes Blog

Threat Score
65/100

Date Published: 2026-01-08

Date Updated: 2026-04-28

...
...

This report analyzes a multi-stage malicious fake WinRAR installer distributed from unofficial Chinese sites that unpacks nested payloads (including a legitimate-looking installer and a malicious HTA), executes memory-only stages, and ultimately drops Winzipper-associated backdoor components (e.g., nimasila360.exe). The author documents static and dynamic analysis techniques, persistence and data-access behavior (Windows Profiles), and provides IOCs (domains and filenames) blocked by Malwarebytes to help detection and mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.