The group is using malicious versions of WinRAR and other legitimate software packages to infect targets, likely via watering-hole attacks.
Source: Threadpost