Multiple threat groups exploited CVE-2023-38831, an arbitrary code execution vulnerability in WinRAR versions before 6.23, in campaigns reported during 2023. The flaw lets a specially crafted archive execute malicious code when a user opens an apparently harmless file inside it. Reported actors included DarkPink, Konni, SideCopy, APT29, UAC-0057, APT28, Sandworm, and APT40. Targets spanned government, defense, energy, financial trading, and cryptocurrency interests across Ukraine, Europe, India, Papua New Guinea, Vietnam, and Malaysia.
Attackers combined phishing and decoy documents with malicious scripts, DLL side-loading, and staged loaders to deliver backdoors, remote access Trojans, and information stealers, including DarkMe, Remcos, PicassoLoader, Rhadamanthys, and BOXRAT. Updating WinRAR to version 6.23 or later addresses the vulnerability. Defenders should identify outdated installations and investigate suspicious archive-opening activity using the published indicators of compromise, behavioral hunting guidance, and archive-focused YARA detection provided in the reports.

See which actors are running it and whether you're in range.
15 events from the most recent confirmed update back to the earliest known activity.
An October 9 campaign targeted Ukraine's government sector with a NATO-themed ZIP archive containing a benign PDF and a CMD file. The archive exploited CVE-2023-38831 to deliver Remcos RAT.
DarkPink exploited CVE-2023-38831 in October 2023 using PDF lures incorporating photocopied government documents. Its archives triggered DLL side-loading and a staged payload chain that installed the TelePowerBot remote-control Trojan.
China-backed APT40 launched a phishing campaign in late August 2023 using Dropbox links to malicious archives containing the exploit, a password-protected PDF, and an LNK file. Its ISLANDSTAGER loader established registry-based persistence and loaded BOXRAT, which used Dropbox for command and control.
UAC-0057 began exploiting CVE-2023-38831 in late August 2023, targeting Ukraine, including its critical energy sector. Its phishing chains used scripts, LNK files, HTA content, and JavaScript, with Cobalt Strike and PicassoLoader among the associated payloads.
Attackers targeted financial traders with ZIP archives exploiting CVE-2023-38831 to deliver DarkMe, malware associated with Evilnum. The execution chain used a Cabinet self-extracting archive, cc.exe, and RunDLL to launch the backdoor.
The report dates use of a download domain associated with a Remcos delivery chain to April 17 through July 18, 2023. The chain used an NSIS installer and the Piskens.For187 PowerShell script to launch GuLoader, which downloaded and decrypted Remcos RAT.
The report places discovery of CVE-2023-38831 in April 2023. The vulnerability affects WinRAR versions before 6.23 and allows attacker-controlled code to execute when a user opens a seemingly benign file inside a crafted archive.
Mysterious Werewolf impersonated Russia's Ministry of Industry and Trade in phishing emails containing archives that exploited CVE-2023-38831. The attack used PowerShell to download an Athena agent, established persistence through a scheduled task running every 10 minutes, and received attacker commands through Discord.
Uptycs published network indicators, process-event hunting logic for suspicious execution from WinRAR temporary paths, and the Uptycs_CVE_2023_38831_PK_FILES YARA rule. The rule checks for a ZIP header and an archive-entry naming pattern associated with exploitation.
Attackers exploited CVE-2023-38831 to deliver Agent Tesla using a CMD file disguised as a PDF inside a same-named folder.
Sandworm distributed invitation-themed phishing emails impersonating a Ukrainian drone warfare training school. The attached ZIP archives exploited CVE-2023-38831 to deploy Rhadamanthys, an information stealer targeting browser, KeePass, and cryptocurrency-wallet data.
Russia-associated APT28 used a crafted HTML page to entice Ukrainian energy-sector victims into downloading an exploit-bearing archive. Another documented APT28 chain opened a decoy PDF, established a reverse SSH shell, and ran IRONJAW to steal browser login data and local-state directories.
APT29 used an archive containing PDF, image, and BAT files under the lure DIPLOMATIC-CAR-FOR-SALE-BMW to target European victims. The BAT script attempted to retrieve a PowerShell payload from an ngrok-hosted endpoint that researchers found inactive during analysis.
Pakistan-associated SideCopy exploited WinRAR using lures impersonating the All India Association of Non Gazetted Officers and files named Achievements_of_DMF. The malicious executable contacted infrastructure associated with remote access Trojan delivery.
North Korea-associated Konni used a Qbao Network-themed archive to target cryptocurrency interests. Its executable masqueraded as an HTML file, checked system architecture, downloaded a payload, and collected system information for transmission to command-and-control infrastructure.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 33 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
5 references tracked. Mallory keeps watching after this page renders.
cloudsecurityalliance.org
Open sourceuptycs.com
Open sourcebi.zone
Open sourceblog.google
Open sourcepaper.seebug.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.