logo

Traders’ dollars in danger: CVE-2023-38831 zero-day vulnerability in WinRAR exploited by cybercriminals to target traders

ID: d0ac9af9-84d4-5fe4-a306-ed7659cba540

STIX ID: report--d0ac9af9-84d4-5fe4-a306-ed7659cba540

Feed Name: Group-IB Blog

Threat Score
78/100

Date Published: 2023-08-23

Date Updated: 2026-04-27

...
...

Group-IB discovered and analyzed a WinRAR zero-day (CVE-2023-38831) actively exploited since April 2023 to spoof file extensions in ZIP archives and execute malicious scripts; attackers distributed weaponized archives on trading forums to deliver DarkMe, GuLoader (CloudEye) and Remcos RAT, resulting in confirmed broker account compromises and attempted fund withdrawals, and Group-IB coordinated disclosure leading to a WinRAR patch (v6.23) in August 2023, while providing detailed IoCs and ATT&CK mappings.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.