Hackers Hide Malware Inside 7-Zip Installers Using a New Evasion Technique

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com


Malware operators are hiding code inside the part of a 7-Zip installer that unpacks files. A seemingly ordinary installation can start while a concealed loader contacts an attacker-controlled server.

Users and analysts may overlook that step because it usually does nothing more than prepare the visible installation.

The samples belong to OpenSUpdater, previously linked to certificate tricks. Attackers put a genuine foobar2000 installer inside a self-extracting archive, making the package look useful.

That credible interior is part of the deception: the familiar software is not necessarily where the harmful behavior begins. Unlike fake archive utility download sites, the danger here sits in the extraction code itself.

Analysts at G Data Software identified the altered component, while ESET detects recent samples as OpenSUpdater, while Microsoft uses the name Snackarcin.

G Data Software said in a report shared with Cyber Security News (CSN) that attackers had rebuilt open-source installer code to conceal a loader. The research establishes neither infection numbers nor a delivery campaign.

Buildup of a 7zip SFX file and its plain text configuration (Source - G Data)
Buildup of a 7zip SFX file and its plain text configuration (Source – G Data)

Checking only the contained program may miss code that runs first. A valid digital signature also does not settle whether the whole package is safe, particularly when the signed publisher has little apparent connection to the bundled program. A familiar wrapper can hide a downloader and an unknown payload.

Hackers Hide Malware Inside 7-Zip Installers

A 7-Zip self-extracting installer unpacks an archive and launches a chosen file. Analysts usually check that chosen file and the installer’s configuration first. Here, both distract from the altered extraction program. That program normally looks standard enough for an analyst to set it aside.

The attackers rebuilt the open-source extraction component and inserted a call to their loader just before the installation progress bar begins. Its starting point, text and imported functions resemble an ordinary component.

A quick review may miss the tampering because the added call sits in the middle of a normal extraction routine, not at its obvious entry point.

The archive contains a real audio-player installer. Its signer, however, is Animated Productions, LLC, which the researchers noted presents itself as a game-app developer. That mismatch raises suspicion.

As with signed installers carrying hidden malware, a valid signature can make an unfamiliar package appear more reassuring than it deserves.

Insertion point of the loader in ExtractArchive() of 7zip SFX stub (Source - G Data)
Insertion point of the loader in ExtractArchive() of 7zip SFX stub (Source – G Data)

The certificate contains repeated padding bytes, while version details resemble unrelated words. Researchers suggested the padding might change a build’s hash without invalidating its signature, but did not confirm the reason. These oddities are clues, not proof.

This is not a flaw in every 7-Zip archive. It is a deliberately modified installer component paired with a legitimate program. Checking only extracted files could miss attacker-added instructions.

The hidden code retrieves an obscured server address and registers using a distinctive byte sequence. A built-in network library then downloads two DLL components and an encrypted data blob. Operators can then supply further code.

The loader runs a function in the first downloaded component, then a function in the second to decrypt the blob. It loads the resulting DLL into memory and calls another function that researchers believe starts the final payload.

They could not obtain those components, leaving the payload’s behavior unverified. In an NSIS variant, attackers changed an open-source NSIS plugin so its loader runs only when a particular function receives an empty string.

Its script stores the server location in compressed form and requests a payload. Earlier trojanized NSIS installer investigations show why the packaging deserves close inspection, although these campaigns differ.

Across the samples, the shared features are a real installer nested inside another installer, a padded but valid certificate, and a loader tucked into modified open-source code.

This differs from other malicious 7-Zip archive campaigns, which used a separate Windows warning-bypass flaw. The distinction matters for investigation.

For analysts, G Data Software recommends staying with suspicious files even when the obvious program looks clean. An installer inside another installer, strange version details or an unusually padded certificate should prompt inspection of less obvious code paths.

Indicators of compromise (IoCs):-

Type Indicator Description
SHA-256 a7666e5aa3c6ecae0295caa7c3f49714eb561d6e1be6807cf1020b79f1902cd0 7-Zip self-extracting sample .
SHA-256 e99a053b9d6a414256177e1529417f85867d6ed355f6009300d626f63429753c 7-Zip self-extracting sample .
SHA-256 ba38916e82c47cff6de71791f179ce762e640e2975e40d6a1803d16ff591b752 Related NSIS sample .
C2 URL hxxps://codeonicinc(dot)com Address associated with samples and , preserved in the source’s defanged format.
C2 URL hxxps://setupsoftwarecenter(dot)com Address associated with sample , preserved in the source’s defanged format.
File name setup.exe Genuine foobar2000 installer embedded in samples and ; not identified as the malicious loader.

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

The post Hackers Hide Malware Inside 7-Zip Installers Using a New Evasion Technique appeared first on Cyber Security News.