Product
WinRAR
- First Reported
- Sep 8, 2025
- Latest Reported
- Sep 8, 2025
Reported Context (1)
- Data collection and exfiltration were performed using WinRAR to compress targeted file shares containing sensitive business documents, which were then transferred via WinSCP to an FTP server hosted by a cloud provider DFIR Report Links Intrusion to Tools Used by Three Ransomware Groups
Malware (5)
People (4)
Threat Actors (3)
MITRE ATT&CK (32)
Vendors (3)
Products (4)
Tools (7)
Countries (1)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.