Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
New Botnet Burns AI Credits, Steals Data
September 29, 2026
New 7-Zip Installer Malware Evades Detection
September 29, 2026
Attackers Exploit Ethereum Blockchain for Covert Malware Communications
September 29, 2026
Home/Threats/New 7-Zip Installer Malware Evades Detection
Threats

New 7-Zip Installer Malware Evades Detection

Key Takeaways Malware operators are embedding malicious loaders within modified 7-Zip self-extracting (SFX) installers, a technique that allows them to bypass traditional detection methods. The...

Sarah simpson
Sarah simpson
September 29, 2026 5 Min Read
3 0

Key Takeaways

  • Malware operators are embedding malicious loaders within modified 7-Zip self-extracting (SFX) installers, a technique that allows them to bypass traditional detection methods.
  • The attack leverages rebuilt open-source installer components, specifically the extraction code, to initiate contact with attacker-controlled servers and download additional payloads.
  • The malware, identified as OpenSUpdater (by ESET) and Snackarcin (by Microsoft), uses legitimate software (like the foobar2000 audio player) as a decoy within the malicious SFX archive.
  • A key evasion tactic involves tampering with the installer’s digital certificate and version information, making the bundled legitimate software appear more trustworthy despite suspicious metadata.
  • The primary threat lies within the subtly altered extraction process, which activates a hidden loader before the visible installation even begins, making it difficult for users and analysts to spot.

Hackers Hide Malware Inside 7-Zip Installers

Cybersecurity researchers have uncovered a sophisticated new method employed by malware operators to evade detection: embedding malicious code directly into the self-extracting (SFX) component of 7-Zip installers. This technique allows a hidden loader to communicate with an attacker’s command-and-control server, all while a seemingly legitimate software installation proceeds in plain sight. Users and security analysts may easily overlook this covert activity, as the initial phase of an SFX installer typically involves only routine file preparation.

Table Of Content

  • Key Takeaways
  • Hackers Hide Malware Inside 7-Zip Installers
  • The Deceptive Nature of Modified Installers
  • Downloader and Related Installer Variants
  • What You Should Do

The discovered samples are attributed to the OpenSUpdater malware family, which has previously been associated with digital certificate manipulation. Attackers are bundling genuine software, such as the foobar2000 audio player, within these self-extracting archives to lend an air of legitimacy to the package. This legitimate internal component is part of the deception, diverting attention from the true point of compromise: the modified extraction code itself, rather than a fake download site or a trojanized application.

Security firm G Data Software first identified the tampered component. ESET subsequently labeled recent samples as OpenSUpdater, while Microsoft refers to this threat as Snackarcin. In a report shared with Cyber Security News (CSN), G Data Software detailed how attackers recompiled the open-source installer code to integrate their concealed loader. The research did not, however, provide specific figures on infection rates or details of the delivery campaigns.

The Deceptive Nature of Modified Installers

A standard 7-Zip self-extracting installer is designed to unpack an archive and then execute a specified file. Typically, analysts would focus their scrutiny on this designated file and the installer’s configuration. However, in this advanced attack, both these elements serve as decoys, redirecting attention away from the subtly altered extraction program. This program is engineered to appear sufficiently benign that analysts might dismiss it during an initial review.

The attackers meticulously rebuilt the open-source extraction component, inserting a call to their malicious loader just before the installation progress bar becomes visible. The malicious code’s entry point, textual data, and imported functions are crafted to closely mimic those of a standard component. A quick analysis might miss this intrusion because the added malicious call is situated within the normal extraction routine, not at an obvious or expected entry point.

Furthermore, the archive contains a legitimate audio player installer, but its digital signer, Animated Productions, LLC, is identified by researchers as a game-app developer. This discrepancy in the publisher’s identity raises immediate suspicion. A valid digital signature, while generally a sign of trustworthiness, can be misleading when the signing entity has no clear connection to the bundled software or when the package itself is otherwise compromised. A familiar outer shell can effectively conceal a downloader and an unknown malicious payload.

Researchers also observed irregularities in the certificate, including repeated padding bytes and version details that appear as unrelated words. They hypothesize that this padding could be an attempt to alter the build’s hash without invalidating the digital signature, though this remains unconfirmed. These anomalies serve as critical indicators for advanced analysis, even if they don’t constitute definitive proof of malice on their own.

It is crucial to understand that this threat does not stem from a vulnerability inherent in every 7-Zip archive. Instead, it is a deliberate modification of an installer component, strategically paired with a legitimate program. Relying solely on checks of the extracted files risks missing the attacker’s embedded instructions. G Data Software emphasizes that this method differs from other malicious 7-Zip campaigns that exploited a Windows warning-bypass flaw, highlighting the importance of distinguishing between various evasion techniques for effective investigation.

Downloader and Related Installer Variants

The concealed code operates by first retrieving an obfuscated server address, then registering itself using a unique byte sequence. Following this, an integrated network library downloads two DLL components and an encrypted data blob. This modular approach allows the attackers to deploy additional arbitrary code as needed.

The loader executes a function in the first downloaded component, then uses a function in the second component to decrypt the data blob. The resulting DLL is then loaded into memory, and another function is called, which researchers believe initiates the final malicious payload. Due to the inability to obtain these final components, the specific behavior of the ultimate payload remains unverified.

In a related variant involving NSIS (Nullsoft Scriptable Install System) installers, attackers modified an open-source NSIS plugin. In this iteration, the loader is configured to execute only when a specific function receives an empty string as input. The NSIS script stores the command-and-control server’s location in a compressed format and then requests the payload. Previous investigations into trojanized NSIS installers underscore the necessity of thoroughly examining packaging, though the specifics of these campaigns vary.

Across all observed samples, common characteristics include a legitimate installer embedded within another installer, a digital certificate that is padded but valid, and a malicious loader hidden within modified open-source code. This sophisticated evasion technique necessitates a deeper level of scrutiny during security analyses.

What You Should Do

  • Scrutinize Installer Origins: Always download software directly from official vendor websites. Avoid third-party download sites or suspicious links.
  • Verify Digital Signatures: While a valid digital signature is a good indicator, check if the publisher’s identity aligns logically with the software being installed. Be wary of mismatches (e.g., a game developer signing an audio player).
  • Conduct Deep Analysis: For security analysts, go beyond surface-level checks of extracted files and visible configurations. Investigate the installer’s self-extraction code paths, looking for unusual modifications or unexpected function calls.
  • Monitor Network Activity: Implement robust network monitoring to detect outbound connections from newly installed software to unfamiliar or suspicious IP addresses or domains.
  • Employ Advanced Endpoint Detection: Utilize Endpoint Detection and Response (EDR) solutions and advanced antivirus software capable of behavioral analysis, which can identify anomalous processes or hidden loader activity.
  • Educate Users: Train users to be suspicious of any unexpected software installations, even if they appear to be for legitimate applications. Emphasize the risks of downloading software from unofficial sources.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackHackerMalwareSecurityThreat

Share Article

Sarah simpson

Sarah simpson

Sarah is a cybersecurity journalist specializing in threat intelligence and malware analysis. With over 8 years of experience covering APT groups, zero-day exploits, and advanced persistent threats, Sarah brings deep technical expertise to breaking cybersecurity news. Previously, she worked as a security researcher at leading threat intelligence firms, where she analyzed malware samples and tracked cybercriminal operations. Sarah holds a Master's degree in Computer Science with a focus on cybersecurity and is a regular contributor to major security conferences.

Previous Post

Attackers Exploit Ethereum Blockchain for Covert Malware Communications

Next Post

New Botnet Burns AI Credits, Steals Data

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
GitHub AI Security Agent Finds 24 Android Vulnerabilities Including Account Takeover Flaws
September 29, 2026
GPT-6 Astra AI Agent Attempts Supply Chain Attacks
September 29, 2026
Threat Actors Weaponize Custom GPTs to Deliver Malware
September 29, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us