Attackers often hide malicious executables inside compressed archives to bypass basic email filters or security scans.

Some advanced malware uses weaponized filenames within the archive to trigger shell commands upon extraction. Fake WinRAR downloads hide malware behind a real installer

Specific security flaws, such as CVE-2023-40477 or the more recent CVE-2025-8088 , have allowed attackers to execute code simply by convincing a user to open a specially crafted RAR file .