Attackers abused the WinRAR remote code execution flaw CVE-2023-38831 in spear-phishing campaigns that used crafted RAR archives to trigger malware execution when victims opened a decoy document. In one case, a phishing email impersonating a consultant from Russia’s Ministry of Industry and Trade targeted a major Russian semiconductor supplier and delivered the Athena agent from the Mythic C2 framework. The archive paired a benign PDF with a malicious script disguised through the trailing-space filename trick tied to the WinRAR flaw; execution led to a PowerShell downloader, retrieval of a decoy PDF and payload from 45.142.212.34, persistence via a scheduled task named aimp2, and command-and-control over Discord-backed channels.
Ukraine’s CERT-UA separately reported active exploitation of the same vulnerability by UAC-0057, which used a malicious archive named Збірник_тез_НУОУ_23.rar to launch a chain involving a BAT file, an LNK shortcut, mshta.exe, and an embedded HTA file. That intrusion dropped a decoy PDF, executed JavaScript identified as a PicassoLoader variant, downloaded an SVG containing an encrypted .NET payload, decrypted it with the Rabbit algorithm, and ultimately deployed Cobalt Strike Beacon. The reports indicate that public proof-of-concept code and broad post-disclosure abuse have made CVE-2023-38831 a practical delivery vector for multiple malware families and threat actors.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
9 events from the most recent confirmed update back to the earliest known activity.
In the same August 31 advisory, CERT-UA warned that CVE-2023-38831 was being actively exploited and noted that public proof-of-concept code existed for generating malicious archives. The agency also published host and network indicators tied to the campaign.
CERT-UA disclosed a cyberattack by UAC-0057 using a malicious archive named "Збірник_тез_НУОУ_23.rar" to exploit CVE-2023-38831. The infection chain used a BAT file, LNK shortcut, mshta, JavaScript, and an SVG-hosted encrypted .NET payload that ultimately deployed Cobalt Strike Beacon.
Group-IB reported DarkMe malware exploiting CVE-2023-38831 and also observed GuLoader and Remcos RAT using the same exploit path. This showed the vulnerability was being adopted by multiple malware operators.
The domains topibuzz.space and windacarmelita.pw, later tied to a CERT-UA-described exploitation campaign, were registered through publicdomainregistry.com. CERT-UA linked them to payload delivery and related network activity.
RARLAB released WinRAR 6.23 to remediate CVE-2023-38831. The fixed version addressed the code execution issue exploited through specially crafted archives.
Artifacts later published by CERT-UA show Beacon-related malware components compiled in late August 2023, including regsvr.dll on August 21 and mokpp9342jktihh.dll on August 29. These timestamps indicate preparation of the payloads used in the campaign.
RARLAB issued a beta patch to address CVE-2023-38831 after the vulnerability was discovered. This was the first cited vendor fix for the WinRAR flaw.
Group-IB discovered the underlying WinRAR ZIP-processing vulnerability CVE-2023-38831. The flaw affects WinRAR versions before 6.23 and can lead to arbitrary code execution via a crafted archive.
Cyble Research and Intelligence Labs identified a spear-phishing campaign targeting a leading Russian semiconductor supplier. The email spoofed a consultant from Russia’s Ministry of Industry and Trade and used a crafted archive named "resultati_sovehchaniya_11_09_2023.rar" to exploit CVE-2023-38831 and deliver the Athena agent of the Mythic C2 framework.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.