Hackers Hide Malware Inside 7-Zip Installers Using a New Evasion Technique
G Data found OpenSUpdater loaders hidden inside tampered 7-Zip SFX extraction code, using nested legitimate installers and padded certificates to evade analysis.
G Data Software identified 7-Zip self-extracting installers whose open-source extraction stub was rebuilt to launch an OpenSUpdater loader (Microsoft: Snackarcin) just before the installation progress bar begins. The packages wrap a genuine foobar2000 installer, carry a padded but valid certificate signed by Animated Productions LLC, and contact C2 domains codeonicinc.com and setupsoftwarecenter.com to download two DLLs and an encrypted blob. The loader loads the decrypted DLL into memory to start a final payload, but researchers could not retrieve those components, and the research establishes neither infection numbers nor a delivery campaign. A related NSIS variant uses a modified open-source plugin triggered by an empty-string function call.