A 19-year-old bug in WinRAR has been exploited in a slew of new campaigns, including one with a never-before-seen payload. The latest are using customized decoy documents with a variety of payloads that are deployed to the Windows Startup folder. Attackers can easily achieve persistence and code execution by creating malicious archives that extract files to sensitive locations, such as the Startup Start Menu folder. The bug is a long-standing one, present in the code base for 19 years before being uncovered in February. The flaws popularity for exploitation may seem counter-intuitive given that the latest version of the utility (5.70) fixes the bug.”]

