Malware operators are hiding code inside the part of a 7-Zip installer that unpacks files. A seemingly ordinary installation can start while a concealed loader contacts an attacker-controlled server.
Users and analysts may overlook that step because it usually does nothing more than prepare the visible installation.
The samples belong to OpenSUpdater, previously linked to certificate tricks. Attackers put a genuine foobar2000 installer inside a self-extracting archive, making the package look useful.
That credible interior is part of the deception: the familiar software is not necessarily where the harmful behavior begins. Unlike fake archive utility download sites, the danger here sits in the extraction code itself.
Analysts at G Data Software identified the altered component, while ESET detects recent samples as OpenSUpdater, while Microsoft uses the name Snackarcin.
G Data Software said in a report shared with Cyber Security News (CSN) that attackers had rebuilt open-source installer code to conceal a loader. The research establishes neither infection numbers nor a delivery campaign.