WinRAR is a legitimate file archiving utility that appears in the provided reporting primarily as a dual-use tool abused by threat actors for collection and staging of data prior to exfiltration. Across multiple incident reports, attackers installed or brought WinRAR into victim environments and used it to collect targeted files into RAR archives, including password-protected archives. In Akira ransomware intrusions, WinRAR was used to stage data for exfiltration, including use of the -hp flag to create password-protected archives such as data.rar through data6.rar from targeted document types on the D: drive. Field Effect also documented WinRAR as part of Akira activity targeting SonicWall SSL VPN environments and mapped its use to ATT&CK T1560.001 (Archive via Utility). Huntress likewise observed an intrusion likely tied to compromised SonicWall VPN access in which the threat actor staged data for exfiltration using WinRAR before later deploying a VMware ESXi exploit toolkit. NCC Group reported WinRAR being installed on a file server during an Everest ransomware incident to archive data for exfiltration, consistent with double-extortion activity. The FBI-led advisory on DPRK Andariel also lists WinRAR among open-source or dual-use tools used by the group. The content additionally references malicious WinRAR self-extracting archives (SFX) as a delivery mechanism in social-engineering activity, and one report claims Bitter APT attacks targeting China and Pakistan leveraged a WinRAR zero-day together with an Office macro and a new C# backdoor. High-confidence behavior directly supported by the content is that WinRAR is commonly used by threat actors to archive and password-protect stolen data in preparation for exfiltration.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Bitter APT Attacks China/Pakistan with WinRAR Zero-Day and New C# Backdoor via Office Macro
...collect the relevant files into RAR archives, sometimes using a version of WinRAR brought into the victim’s environment...
Additional tools were recovered during the incident, including ... the archiving tool WinRAR ...
18 distinct techniques documented for this family, organized by ATT&CK tactic.
the threat actor connected to the environment via the VPN and used Windows Management Instrumentation (WMI) ( Windows Management Instrumentation [T1047]) to remotely launch a tasklist
"C:\Windows\System32\cmd.exe" /c %AppData%\Roaming\Yandex\winrar.exe x ...
When testing, it is important to reproduce the ways attackers typically run these tools. For example, they may rename executable files or place them in unusual directories.
launched procdump.exe, which was disguised as wininit.exe ( Masquerading: Match Legitimate Name or Location [T1036.005]). After this, the threat actor placed and ran winrar, which was also disguised as wininit.exe
Technical details | Collection TA0009 | Data from Local System T1005
The actor(s) collect [T1114] and compress [T1560.001] the mailbox data with 7Zip or WinRAR before exfiltrating victim emails.
We assume the attacker ran this command periodically in order to get only new documents and minimize the quantity of exfiltrated data.
they began to use WinRAR to compress a collection of files for exfiltration... and threatened data exposure if the victim did not comply
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
WinRAR was used to stage and password-protect stolen data prior to exfiltration in an Akira-affiliated intrusion.
Legitimate archiving/SFX tool referenced as being abused to deliver a malicious payload in a social-engineering campaign.
Legitimate file archiver referenced in the context of a zero-day vulnerability being used in attacks.
Legitimate archiver used to compress/stage collected data prior to exfiltration in the observed ransomware intrusion chain.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.