OpenSUpdater Malware Hides Inside 7-Zip Installers to Evade Detection
OpenSUpdater operators hide a reflective loader inside recompiled 7-Zip SFX stubs, evading analysis while beaconing C2, downloading DLLs, and executing payloads in memory.
GData analysis shows OpenSUpdater inserts a malicious loader into the 7-Zip SFX ExtractArchive routine of recompiled installer stubs, packaging a genuine foobar2000 setup.exe signed by unrelated publisher Animated Productions, LLC. Padded certificate data alters file hashes between builds without invalidating signatures, frustrating hash-based detection. The loader performs C2 beaconing with a magic-byte client marker, downloads two DLLs and an encrypted blob via statically compiled cURL, then reflectively maps and executes the decrypted DLL's cx3 export. NSIS variants insert the loader into the EmbedHtml::GetUrl() function of the open-source EmbedHtml plugin, activating on an empty-string argument.