WinRAR Zero-Day Exploit Plants Malware During Extraction

·
WinRAR Zero-Day Exploit Plants Malware During Extraction

BERLIN – Security researchers at the Fraunhofer Institute and an incident-response collective calling itself Grayhand disclosed a WinRAR zero-day on Friday that allows code execution the moment a booby-trapped archive is extracted. The teams, working with Germany’s BSI and two EU bank CERTs, say the exploit has already been used in targeted intrusions against financial trading desks and treasury ops. Indicators point to spear-phished archives posing as settlement packets and audit bundles. WinRAR’s publisher pushed an emergency build overnight and urged “immediate” updating across Windows estates, while gateway vendors rushed mitigations for mail and file scanners that auto-expand attachments for inspection.

The impossible part is where the bug lives: not in a file, but in the ratio. Grayhand’s write-up calls it a “compression grammar fault,” nicknamed ATTIC/GRAMMARJACK, where a crafted sequence of back-references and dictionary resets forces the extractor into a mis-parsed state that jumps into attacker-controlled instruction tables generated by the decompressed pattern itself. In plain English, the code rides inside the timing and repetition of the data—malware as meter. When the archive expands, the parser briefly believes the next token is a handler address. No macro prompts, no hidden executables in the tree; the payload is the rhythm. One analyst described it as “teaching the zipper to hum a tune that opens the door.”

The truth bomb is dumber and scarier: half of corporate Europe still treats a 1990s shareware utility as critical infrastructure. A leaked memo from a major clearing bank’s “Records & Receipts” group admits that quarterly archives of SWIFT attestations, HR payroll bundles, and vendor backups are “RAR-standardized for legacy comfort.” Email gateways proudly “flatten” attachments for CDR scanning—by auto-extracting them first—putting the most privileged machines in the blast radius. Procurement never bought proper licenses because WinRAR never really stops working, and the patch cadence for “trialware everyone forgot to pay for” is whatever the help desk feels like. “We designed our controls around files,” a European regulator said in a call Thursday, “and this thing weaponizes the process.”

Defense guidance is already a museum of the absurd. BSI’s temporary advisory recommends air-gap decompression kiosks—a literal cart with a fresh image, a printer, and no NIC—until fleet patching catches up. Two exchanges told members to pause the practice of “pre-unboxing” counterparties’ attachments on secure mail relays. Insurers have begun asking for screenshots of the WinRAR About dialog as part of renewal questionnaires, while red teams report that the same parsing lineage lurks in firmware unpackers for printers, NAS boxes, and security cameras. Banks that run e-discovery or trade-surveillance pipelines on overnight batch shares discovered those jobs were the perfect detonation timers: clean at 5 p.m., compromised by 6 a.m., with forensics blaming the janitor’s vacuum for the network spike.

The patched build closes the specific grammar fault, but samples captured late Friday hint at a nastier evolution: archives that carry negative entries—placeholders that don’t unpack files so much as unpack your machine by coercing the extractor into reading local paths as if they were part of the archive. One lab recovered a bundle that expanded to an empty folder and a perfectly normal checksum, yet the SIEM lit up with outbound traffic as if a ghost directory had been exfiltrated. “Opening the wrong ZIP could open your whole network,” a researcher said, and the line turns out to be literal. If compression is the art of removing what doesn’t matter, attackers have found a way to remove the only thing that did: your permission.

Share: X Facebook Reddit

More Stories

Jerusalem Protesters Form Massive Human QR Code Outside Netanyahu’s Residence

Aerial view of thousands of protesters forming a giant scannable QR code outside government buildings

Thousands of protesters converged on Prime Minister Benjamin Netanyahu’s residence in Jerusalem, but instead of chanting slogans, they formed a massive human QR code visible from the air. Scanning the code redirected users to a website titled ‘The Receipts,’ hosting a sprawling archive of alleged corruption documents. The demonstration, coordinated via encrypted group chats, caused confusion among police drones, which reportedly misread the code as a...


Congress Passes Bill Mandating All Laws Be Written in Comic Sans to ‘Increase Relatability’

A humorous depiction of Congress members discussing new legislation written in Comic Sans, with exaggerated expressions of confusion and amusement.

In a move hailed by supporters as a “bold step toward a more approachable democracy,” Congress has passed H.R. 5472, officially requiring all federal legislation to be drafted and published exclusively in Comic Sans. The bill, championed by Senator John Fetterman (D-PA) and Representative Marjorie Taylor Greene (R-GA) in a rare bipartisan effort, sailed through both chambers late last night after weeks of tense debate. Proponents argue that the shift will “humanize” dense legal documents, making them less intimidating to the average American. President Biden is expected to sign the bill into law this afternoon during a Rose Garden ceremony featuring cupcakes and balloon animals. The change, however, is far from symbolic. According to section 4(b)...