Hackers Hide Malware Inside 7-Zip Installers Using a New Evasion Technique
G Data found OpenSUpdater loaders hidden inside tampered 7-Zip SFX extraction code, using nested legitimate installers and padded certificates to evade analysis.
G Data Software identified 7-Zip self-extracting installers whose open-source extraction stub was rebuilt to launch an OpenSUpdater loader (Microsoft: Snackarcin) just before the installation progress bar begins. The packages wrap a genuine foobar2000 installer, carry a padded but valid certificate signed by Animated Productions LLC, and contact C2 domains codeonicinc.com and setupsoftwarecenter.com to download two DLLs and an encrypted blob. The loader loads the decrypted DLL into memory to start a final payload, but researchers could not retrieve those components, and the research establishes neither infection numbers nor a delivery campaign. A related NSIS variant uses a modified open-source plugin triggered by an empty-string function call.
- Tampered 7-Zip SFX stub launches OpenSUpdater loader before installation starts
- Genuine foobar2000 installer and padded valid certificate increase deception
- Loader downloads two DLLs plus encrypted blob from attacker C2 domains
- Final payload never retrieved; infection numbers and campaign unknown
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| sha256 | a7666e5aa3c6ecae0295caa7c3f49714eb561d6e1be6807cf1020b79f1902cd0 | s of compromise (IoCs):- Type Indicator Description SHA-256 a7666e5aa3c6ecae0295caa7c3f49714eb561d6e1be6807cf1020b79f1902cd0 7-Zip self-extracting sample . SHA-256 e99a053b9d6a41425617 |
| sha256 | ba38916e82c47cff6de71791f179ce762e640e2975e40d6a1803d16ff591b752 | 009300d626f63429753c 7-Zip self-extracting sample . SHA-256 ba38916e82c47cff6de71791f179ce762e640e2975e40d6a1803d16ff591b752 Related NSIS sample . C2 URL hxxps://codeonicinc(dot)com Ad |
| sha256 | e99a053b9d6a414256177e1529417f85867d6ed355f6009300d626f63429753c | 807cf1020b79f1902cd0 7-Zip self-extracting sample . SHA-256 e99a053b9d6a414256177e1529417f85867d6ed355f6009300d626f63429753c 7-Zip self-extracting sample . SHA-256 ba38916e82c47cff6de7 |
| url | https://codeonicinc(dot | 640e2975e40d6a1803d16ff591b752 Related NSIS sample . C2 URL hxxps://codeonicinc(dot)com Address associated with samples and , preserved in the |
| url | https://setupsoftwarecenter(dot | les and , preserved in the source’s defanged format. C2 URL hxxps://setupsoftwarecenter(dot)com Address associated with sample , preserved in the sourc |
Full article854 words · extracted from cybersecuritynews.com · click to collapse
Malware operators are hiding code inside the part of a 7-Zip installer that unpacks files. A seemingly ordinary installation can start while a concealed loader contacts an attacker-controlled server.
Users and analysts may overlook that step because it usually does nothing more than prepare the visible installation.
The samples belong to OpenSUpdater, previously linked to certificate tricks. Attackers put a genuine foobar2000 installer inside a self-extracting archive, making the package look useful.
That credible interior is part of the deception: the familiar software is not necessarily where the harmful behavior begins. Unlike fake archive utility download sites, the danger here sits in the extraction code itself.
Analysts at G Data Software identified the altered component, while ESET detects recent samples as OpenSUpdater, while Microsoft uses the name Snackarcin.
G Data Software said in a report shared with Cyber Security News (CSN) that attackers had rebuilt open-source installer code to conceal a loader. The research establishes neither infection numbers nor a delivery campaign.
.webp)
Checking only the contained program may miss code that runs first. A valid digital signature also does not settle whether the whole package is safe, particularly when the signed publisher has little apparent connection to the bundled program. A familiar wrapper can hide a downloader and an unknown payload.
Hackers Hide Malware Inside 7-Zip Installers
A 7-Zip self-extracting installer unpacks an archive and launches a chosen file. Analysts usually check that chosen file and the installer’s configuration first. Here, both distract from the altered extraction program. That program normally looks standard enough for an analyst to set it aside.
The attackers rebuilt the open-source extraction component and inserted a call to their loader just before the installation progress bar begins. Its starting point, text and imported functions resemble an ordinary component.
A quick review may miss the tampering because the added call sits in the middle of a normal extraction routine, not at its obvious entry point.
The archive contains a real audio-player installer. Its signer, however, is Animated Productions, LLC, which the researchers noted presents itself as a game-app developer. That mismatch raises suspicion.
As with signed installers carrying hidden malware, a valid signature can make an unfamiliar package appear more reassuring than it deserves.
%20of%207zip%20SFX%20stub%20(Source%20-%20G%20Data).webp)
The certificate contains repeated padding bytes, while version details resemble unrelated words. Researchers suggested the padding might change a build’s hash without invalidating its signature, but did not confirm the reason. These oddities are clues, not proof.
This is not a flaw in every 7-Zip archive. It is a deliberately modified installer component paired with a legitimate program. Checking only extracted files could miss attacker-added instructions.
The hidden code retrieves an obscured server address and registers using a distinctive byte sequence. A built-in network library then downloads two DLL components and an encrypted data blob. Operators can then supply further code.
The loader runs a function in the first downloaded component, then a function in the second to decrypt the blob. It loads the resulting DLL into memory and calls another function that researchers believe starts the final payload.
They could not obtain those components, leaving the payload’s behavior unverified. In an NSIS variant, attackers changed an open-source NSIS plugin so its loader runs only when a particular function receives an empty string.
Its script stores the server location in compressed form and requests a payload. Earlier trojanized NSIS installer investigations show why the packaging deserves close inspection, although these campaigns differ.
Across the samples, the shared features are a real installer nested inside another installer, a padded but valid certificate, and a loader tucked into modified open-source code.
This differs from other malicious 7-Zip archive campaigns, which used a separate Windows warning-bypass flaw. The distinction matters for investigation.
For analysts, G Data Software recommends staying with suspicious files even when the obvious program looks clean. An installer inside another installer, strange version details or an unusually padded certificate should prompt inspection of less obvious code paths.
Indicators of compromise (IoCs):-
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.