Malware News Hackers Hide Malware Inside 7-Zip Installers Using a New Evasion Technique

Security News
4 Replies 119 Views

Brownie2019

Level 23
Verified
Well-known
Forum Veteran
Malware operators are hiding code inside the part of a 7-Zip installer that unpacks files. A seemingly ordinary installation can start while a concealed loader contacts an attacker-controlled server.

Users and analysts may overlook that step because it usually does nothing more than prepare the visible installation.

The samples belong to OpenSUpdater, previously linked to certificate tricks. Attackers put a genuine foobar2000 installer inside a self-extracting archive, making the package look useful.

That credible interior is part of the deception: the familiar software is not necessarily where the harmful behavior begins. Unlike fake archive utility download sites, the danger here sits in the extraction code itself.

Analysts at G Data Software identified the altered component, while ESET detects recent samples as OpenSUpdater, while Microsoft uses the name Snackarcin.

G Data Software said in a report shared with Cyber Security News (CSN) that attackers had rebuilt open-source installer code to conceal a loader. The research establishes neither infection numbers nor a delivery campaign.
Full Story:
 
Full Story: (link omitted)


Hi Brownie2019, this is a clever hiding place, but the headline needs one correction: G DATA did not find malware in official 7-Zip installers. The samples were malicious self-extracting archives built from a modified 7-Zip SFX module. There is no reported 7-Zip vulnerability or supply-chain compromise here.

G DATA’s investigation says the attackers inserted their loader into the SFX extraction routine, immediately before the normal progress-bar initialization. That placement matters because an analyst may inspect the archive configuration and enclosed files while assuming the familiar extraction stub is standard code.

The package then runs two tracks:

  • A genuine foobar2000 installer provides the expected visible installation.
  • The altered extraction stub contacts its command-and-control server, downloads two DLLs and an encrypted blob, decrypts the blob and maps the resulting DLL directly into memory.

That makes the legitimate installer camouflage, not the initial source of the malicious behaviour. Seeing the expected application install successfully therefore proves very little—rather like receiving the correct pizza from someone who also copied your house key.

One useful limitation in the findings is that G DATA could not obtain the final components from the server. Consequently, the loader’s mechanism is documented, but the final payload and its intended actions were not established. The research also does not provide infection totals or identify a particular delivery campaign.

Practical implications​


  • Source still matters. Download 7-Zip, foobar2000 and other software directly from their official sites rather than advertisements, bundles or third-party download pages.
  • Check the signer’s identity, not merely whether Windows says the signature is valid. These samples were reportedly signed by Animated Productions, LLC. A valid signature proves that the signed file has not changed since signing; it does not prove the signer is the expected software vendor or that the file is harmless.
  • Do not clear an installer merely because its enclosed application is genuine. The outer executable, extraction stub and anything launched during setup all require consideration.
  • Anyone who actually executed a suspected sample should treat that as possible code execution, disconnect the affected system from the network and seek individualized help from MalwareTips’ Malware Removal Assistance team. A clean initial scan would not by itself exclude a downloaded or memory-loaded payload.

So the technique is noteworthy, but “trojanized 7-Zip SFX package” is substantially more accurate than “malware inside 7-Zip installers.”

Sources
 
Thanks @Bot as that is what I was wondering, where is it being download from, the official site? Which in that case would be a disaster.


Exactly—if the files had come from 7-zip.org, this would be a supply-chain compromise and a much bigger story. Nothing in the research indicates that happened.

The attackers used 7-Zip’s publicly available source code to compile their own modified self-extracting stub. The resulting package contained a genuine foobar2000 installer, but it was not an official 7-Zip installer and was reportedly signed by “Animated Productions, LLC,” not the expected software publisher.

The G DATA report does not establish where these malicious packages were distributed or how victims encountered them. So the delivery source remains unknown; there is no evidence pointing to the official 7-Zip site.

That is why the headline is rather unfortunate: “malware hidden in a modified 7-Zip SFX stub” is accurate, while “inside 7-Zip installers” sounds as though the official downloads were poisoned.

Sources
 
Exactly, and IMO, another "scare, clickbait" article.
The G DATA report does not establish where these malicious packages were distributed or how victims encountered them. So the delivery source remains unknown;
 
Back
Top