OpenSUpdater (Microsoft: 'Snackarcin') Hides Loader in Recompiled 7-Zip SFX Installers Wrapped Around Genuine foobar2000 Setup
G Data found OpenSUpdater loaders embedded in recompiled 7-Zip SFX extraction stubs that wrap a genuine foobar2000 installer, use padded certificates to defeat hash-based detection, and download in-memory payloads from attacker C2 domains; the final payload…
Analysis by G Data (GData) Software, reported on 2026-09-29 by both GBHackers and Cyber Security News, shows that the malware tracked as OpenSUpdater (named 'Snackarcin' by Microsoft) hides its loader inside 7-Zip self-extracting installer stubs that were rebuilt from the open-source extraction code. The loader is inserted into the SFX ExtractArchive routine so that it executes just before the installation progress bar begins, diverting analyst attention away from the trusted decompression stub. The tampered packages wrap a genuine foobar2000 setup.exe signed by an unrelated publisher, Animated Productions, LLC; padded certificate data alters file hashes between builds without invalidating the signatures, frustrating hash-based detection. The loader performs C2 beaconing — using a magic-byte client marker, per GBHackers — to the domains codeonicinc.com and setupsoftwarecenter.com, then downloads two DLLs and an encrypted blob via statically compiled cURL. It reflectively loads the decrypted DLL into memory and executes its cx3 export to start a final payload, but researchers could not retrieve those payload components, and the research establishes neither infection numbers nor how the installers are delivered. A related NSIS variant hides the loader inside the open-source EmbedHtml plugin's GetUrl() function, triggered when called with an empty-string argument.
- Researcher: G Data (GData) Software; malware family OpenSUpdater, which Microsoft calls Snackarcin.
- Malicious loader inserted into the ExtractArchive routine of recompiled 7-Zip SFX stubs, launching just before the installation progress bar begins.
- Packages wrap a genuine foobar2000 setup.exe signed by unrelated publisher Animated Productions, LLC.
- Padded certificate data changes file hashes between builds while keeping the signatures valid, evading hash-based detection.
- C2 domains contacted: codeonicinc.com and setupsoftwarecenter.com; beaconing uses a magic-byte client marker (per GBHackers).
- Loader downloads two DLLs and an encrypted blob via statically compiled cURL, then reflectively maps the decrypted DLL in memory and executes its cx3 export.
- Final payload components were never retrieved; infection numbers and the delivery campaign remain unknown.
- NSIS variant hides the loader in the open-source EmbedHtml plugin's GetUrl() function, activated by an empty-string function-call argument.
Coverage timelineoldest first · each row is one article
- · 2d agoOpenSUpdater Malware Hides Inside 7-Zip Installers to Evade Detection
GBHackers· 52
OpenSUpdater operators hide a reflective loader inside recompiled 7-Zip SFX stubs, evading analysis while beaconing C2, downloading DLLs, and executing payloads in memory.
- · 2d agoHackers Hide Malware Inside 7-Zip Installers Using a New Evasion Technique
Cyber Security News· 52
G Data found OpenSUpdater loaders hidden inside tampered 7-Zip SFX extraction code, using nested legitimate installers and padded certificates to evade analysis.