Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
7-Zip Mark-of-the-Web Bypass Lets Malicious Files Evade Windows SmartScreen
August 5, 2026
Microsoft Defender Stops QNET Ransomware Attack in 128 Seconds
August 5, 2026
Critical Veeam ONE Vulnerabilities Let Attackers Execute Code
August 5, 2026
Home/CyberSecurity News/7-Zip Mark-of-the-Web Bypass Lets Malicious Files Evade Windows SmartScreen
CyberSecurity News

7-Zip Mark-of-the-Web Bypass Lets Malicious Files Evade Windows SmartScreen

Key Takeaways A newly identified behavior in 7-Zip allows malicious files to bypass Windows SmartScreen warnings by failing to propagate the Mark-of-the-Web (MotW) tag. This is not a vulnerability in...

Jennifer sherman
Jennifer sherman
August 5, 2026 4 Min Read
2 0

Key Takeaways

  • A newly identified behavior in 7-Zip allows malicious files to bypass Windows SmartScreen warnings by failing to propagate the Mark-of-the-Web (MotW) tag.
  • This is not a vulnerability in 7-Zip’s code but rather a security-control gap stemming from the archiver’s default handling of download-origin metadata.
  • Attackers can leverage this by delivering malware via ZIP archives, which, when extracted with 7-Zip (version 24.09 and earlier), lose their MotW, allowing executables to launch without SmartScreen scrutiny.
  • The issue primarily affects 7-Zip’s default configuration, where the “Propagate Zone.Id stream” setting is set to “No.”
  • Users and organizations should update 7-Zip and configure it to propagate Zone.Id streams to maintain this critical security layer.

7-Zip Behavior Evades Windows SmartScreen Warnings

A recently documented interaction involving the popular 7-Zip archiving tool and Windows’ native security features reveals a significant gap that could allow malicious files to execute without triggering vital SmartScreen warnings. This behavior, identified by security researchers, enables downloaded executables to shed their Mark-of-the-Web (MotW) metadata when extracted by 7-Zip, thereby circumventing a crucial layer of defense designed to protect users from suspicious content.

Table Of Content

  • Key Takeaways
  • 7-Zip Behavior Evades Windows SmartScreen Warnings
  • The Mark-of-the-Web Bypass Explained
  • Why the Delivery Chain Matters
  • What You Should Do

ZIP archives are frequently employed in phishing and social engineering attacks, often disguised as invoices, updates, or shared documents. The newly observed behavior means an attacker can deliver a malicious archive, convince a user to extract it with 7-Zip, and then rely on the extracted, now unmarked, file to launch without the expected SmartScreen prompt.

This is not an exploit targeting a flaw within 7-Zip’s codebase. Instead, it represents a gap in security control arising from how 7-Zip, by default, manages the metadata indicating a file’s download origin.

The Mark-of-the-Web Bypass Explained

Analysts at Attackd uncovered this behavior during their investigations into phishing delivery methods and endpoint protection efficacy. Attackd said in a report that 7-Zip version 24.09 failed to transfer the Mark-of-the-Web tag from a downloaded ZIP archive to the executable files extracted within it. A detailed report on the findings is also available here. While other security measures like antivirus and endpoint monitoring might still detect threats, the absence of a SmartScreen prompt removes a crucial early warning system for users.

Mark-of-the-Web (MotW) is a Windows security feature that attaches metadata to files downloaded from the internet. This metadata, stored in a Zone.Identifier data stream, typically indicates that the file originated from the “Internet zone” (ZoneId=3). This tag isn’t a detection engine itself; rather, it signals to Windows and compatible security components, like SmartScreen, that the file requires additional scrutiny.

When a MotW-tagged executable is launched via File Explorer, SmartScreen performs a reputation check before allowing it to run. If a program is new, unsigned, or lacks an established reputation, SmartScreen will likely display a warning, even if other endpoint security products haven’t flagged it. This distinction is critical: bypassing one security layer doesn’t mean an attacker has defeated all defenses, but it significantly lowers the bar for successful social engineering.

Attackd’s testing confirmed that when a ZIP archive carrying MotW was extracted using 7-Zip 24.09, the extracted files lacked the Zone.Identifier stream. Consequently, SmartScreen was not invoked when these files were subsequently launched through Explorer. This behavior echoes previous MotW weaknesses related to archive handling, such as those exploited in SmokeLoader 7-Zip zero-day attacks. However, this current finding highlights a default configuration issue, not a new CVE-assigned vulnerability.

Interestingly, Windows 11’s built-in Explorer extraction functionality now correctly propagates MotW even from password-protected ZIP files. In contrast, 7-Zip’s “Propagate Zone.Id stream” setting defaults to “No” in the tested versions. Changing this setting to “Yes,” or enabling the specific option for Office files where relevant, ensures the metadata is carried over to extracted content.

Why the Delivery Chain Matters

This research underscores the importance of realistic testing in cybersecurity. Phishing simulations and defensive reviews must accurately mimic how users interact with files. For example, a malicious payload directly copied onto a test system might lack MotW, leading to misleading test results because SmartScreen would never be triggered. Various delivery methods—browser downloads, archive extractions, Explorer launches, PowerShell executions, and files from network shares—can all encounter different security checkpoints.

Researchers also confirmed that browser downloads, including those initiated via blob or data URLs, consistently received the Internet-zone mark in tests conducted with Chrome, Edge, Brave, and Firefox. While Edge can perform an earlier reputation check during the download process, other browsers typically rely on their own download protections and Windows’ checks at launch. This distinction is vital when analyzing SmartScreen bypass campaigns.

What You Should Do

  • Update 7-Zip: Ensure all 7-Zip installations are updated to the latest available version.
  • Configure 7-Zip for MotW Propagation: Review 7-Zip deployments across managed endpoints and configure the “Propagate Zone.Id stream” setting to “Yes” to ensure download-origin metadata is preserved.
  • Validate Settings: Test representative archive and browser download paths to confirm that MotW propagation is functioning as expected across your environment.
  • Maintain Endpoint Monitoring: Continue to rely on comprehensive endpoint detection and response (EDR) solutions and antivirus software as primary layers of defense.
  • User Education: Educate staff to remain vigilant and not assume a file is safe simply because a warning prompt did not appear. Emphasize caution with unsolicited compressed files.
  • Stay Informed: Keep abreast of new findings related to archive tool vulnerabilities and secure configurations, as issues beyond MotW propagation can also pose risks.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEExploitphishingSecurityVulnerabilityzero-day

Share Article

Jennifer sherman

Jennifer sherman

Jennifer is a cybersecurity news reporter covering data breaches, ransomware campaigns, and dark web markets. With a background in incident response, Jennifer provides unique insights into how organizations respond to cyber attacks and the evolving tactics of threat actors. Her reporting has covered major breaches affecting millions of users and has helped organizations understand emerging threats. Jennifer combines technical knowledge with investigative journalism to deliver in-depth coverage of cybersecurity incidents.

Previous Post

Microsoft Defender Stops QNET Ransomware Attack in 128 Seconds

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
CISA Warns of Apache Tomcat Encryption Flaw Actively Exploited
August 5, 2026
Critical RCE Flaw in Cursor, VS Code, and Google Antigravity Exposes 50M Developers
August 5, 2026
Critical Microsoft Copilot Vulnerability Lets Attackers Hijack Accounts
August 4, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us