Multiple State-Sponsored Groups Exploit WinRAR Vulnerability in Phishing Attacks

Red | Vulnerability Report

A series of phishing attacks linked to a Russian state-sponsored group, leveraging a WinRAR vulnerability to steal data, including browser credentials via PowerShell commands and exfiltrating it through a legitimate service.