Research by security firms like Trend Micro and Proofpoint has identified several threats delivered via this method:
: Ensure WinRAR or 7-Zip are updated to the latest versions to patch known execution vulnerabilities.
: Full system compromise without the user realizing they ran an executable. Protective Measures
: Attackers create a .rar archive where a file and a folder have the same name.
: When a user double-clicks the file inside the archive, the vulnerability causes the application to execute a malicious script from the identically named folder instead.
: A sophisticated downloader used to deliver other malware families while evading detection.