New 7-Zip Installer Malware Evades Detection
Key Takeaways Malware operators are embedding malicious loaders within modified 7-Zip self-extracting (SFX) installers, a technique that allows them to bypass traditional detection methods. The...
Key Takeaways
- Malware operators are embedding malicious loaders within modified 7-Zip self-extracting (SFX) installers, a technique that allows them to bypass traditional detection methods.
- The attack leverages rebuilt open-source installer components, specifically the extraction code, to initiate contact with attacker-controlled servers and download additional payloads.
- The malware, identified as OpenSUpdater (by ESET) and Snackarcin (by Microsoft), uses legitimate software (like the foobar2000 audio player) as a decoy within the malicious SFX archive.
- A key evasion tactic involves tampering with the installer’s digital certificate and version information, making the bundled legitimate software appear more trustworthy despite suspicious metadata.
- The primary threat lies within the subtly altered extraction process, which activates a hidden loader before the visible installation even begins, making it difficult for users and analysts to spot.
Hackers Hide Malware Inside 7-Zip Installers
Cybersecurity researchers have uncovered a sophisticated new method employed by malware operators to evade detection: embedding malicious code directly into the self-extracting (SFX) component of 7-Zip installers. This technique allows a hidden loader to communicate with an attacker’s command-and-control server, all while a seemingly legitimate software installation proceeds in plain sight. Users and security analysts may easily overlook this covert activity, as the initial phase of an SFX installer typically involves only routine file preparation.
Table Of Content
The discovered samples are attributed to the OpenSUpdater malware family, which has previously been associated with digital certificate manipulation. Attackers are bundling genuine software, such as the foobar2000 audio player, within these self-extracting archives to lend an air of legitimacy to the package. This legitimate internal component is part of the deception, diverting attention from the true point of compromise: the modified extraction code itself, rather than a fake download site or a trojanized application.
Security firm G Data Software first identified the tampered component. ESET subsequently labeled recent samples as OpenSUpdater, while Microsoft refers to this threat as Snackarcin. In a report shared with Cyber Security News (CSN), G Data Software detailed how attackers recompiled the open-source installer code to integrate their concealed loader. The research did not, however, provide specific figures on infection rates or details of the delivery campaigns.
The Deceptive Nature of Modified Installers
A standard 7-Zip self-extracting installer is designed to unpack an archive and then execute a specified file. Typically, analysts would focus their scrutiny on this designated file and the installer’s configuration. However, in this advanced attack, both these elements serve as decoys, redirecting attention away from the subtly altered extraction program. This program is engineered to appear sufficiently benign that analysts might dismiss it during an initial review.
The attackers meticulously rebuilt the open-source extraction component, inserting a call to their malicious loader just before the installation progress bar becomes visible. The malicious code’s entry point, textual data, and imported functions are crafted to closely mimic those of a standard component. A quick analysis might miss this intrusion because the added malicious call is situated within the normal extraction routine, not at an obvious or expected entry point.
Furthermore, the archive contains a legitimate audio player installer, but its digital signer, Animated Productions, LLC, is identified by researchers as a game-app developer. This discrepancy in the publisher’s identity raises immediate suspicion. A valid digital signature, while generally a sign of trustworthiness, can be misleading when the signing entity has no clear connection to the bundled software or when the package itself is otherwise compromised. A familiar outer shell can effectively conceal a downloader and an unknown malicious payload.
Researchers also observed irregularities in the certificate, including repeated padding bytes and version details that appear as unrelated words. They hypothesize that this padding could be an attempt to alter the build’s hash without invalidating the digital signature, though this remains unconfirmed. These anomalies serve as critical indicators for advanced analysis, even if they don’t constitute definitive proof of malice on their own.
It is crucial to understand that this threat does not stem from a vulnerability inherent in every 7-Zip archive. Instead, it is a deliberate modification of an installer component, strategically paired with a legitimate program. Relying solely on checks of the extracted files risks missing the attacker’s embedded instructions. G Data Software emphasizes that this method differs from other malicious 7-Zip campaigns that exploited a Windows warning-bypass flaw, highlighting the importance of distinguishing between various evasion techniques for effective investigation.
Downloader and Related Installer Variants
The concealed code operates by first retrieving an obfuscated server address, then registering itself using a unique byte sequence. Following this, an integrated network library downloads two DLL components and an encrypted data blob. This modular approach allows the attackers to deploy additional arbitrary code as needed.
The loader executes a function in the first downloaded component, then uses a function in the second component to decrypt the data blob. The resulting DLL is then loaded into memory, and another function is called, which researchers believe initiates the final malicious payload. Due to the inability to obtain these final components, the specific behavior of the ultimate payload remains unverified.
In a related variant involving NSIS (Nullsoft Scriptable Install System) installers, attackers modified an open-source NSIS plugin. In this iteration, the loader is configured to execute only when a specific function receives an empty string as input. The NSIS script stores the command-and-control server’s location in a compressed format and then requests the payload. Previous investigations into trojanized NSIS installers underscore the necessity of thoroughly examining packaging, though the specifics of these campaigns vary.
Across all observed samples, common characteristics include a legitimate installer embedded within another installer, a digital certificate that is padded but valid, and a malicious loader hidden within modified open-source code. This sophisticated evasion technique necessitates a deeper level of scrutiny during security analyses.
What You Should Do
- Scrutinize Installer Origins: Always download software directly from official vendor websites. Avoid third-party download sites or suspicious links.
- Verify Digital Signatures: While a valid digital signature is a good indicator, check if the publisher’s identity aligns logically with the software being installed. Be wary of mismatches (e.g., a game developer signing an audio player).
- Conduct Deep Analysis: For security analysts, go beyond surface-level checks of extracted files and visible configurations. Investigate the installer’s self-extraction code paths, looking for unusual modifications or unexpected function calls.
- Monitor Network Activity: Implement robust network monitoring to detect outbound connections from newly installed software to unfamiliar or suspicious IP addresses or domains.
- Employ Advanced Endpoint Detection: Utilize Endpoint Detection and Response (EDR) solutions and advanced antivirus software capable of behavioral analysis, which can identify anomalous processes or hidden loader activity.
- Educate Users: Train users to be suspicious of any unexpected software installations, even if they appear to be for legitimate applications. Emphasize the risks of downloading software from unofficial sources.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.