logo

WinRAR Flaw Exposes Users To Apanyan, AsyncRAT, Murk

ID: 53d78a2e-f51c-5a4b-847e-6ee8b3114255

STIX ID: report--53d78a2e-f51c-5a4b-847e-6ee8b3114255

Feed Name: Cyble Blog

Threat Score
75/100

Date Published: 2025-12-04

Date Updated: 2026-07-17

...
...

**Executive summary:** This report details an active cybercrime campaign abusing WinRAR CVE-2023-38831 to execute a hidden CMD from crafted RAR archives (often distributed via adult or fake adult sites), which downloads a BAT/PowerShell chain that deploys Apanyan Stealer, Murk‑Stealer and AsyncRAT to exfiltrate credentials and provide remote access; the document includes a full technical analysis, anti‑VM checks, MITRE ATT&CK mapping, and IOCs (hashes and URLs) for detection and mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.