logo

Attackers Use Malformed ZIP Archives to Evade Antivirus and EDR Tools

ID: 5dae5306-c070-5851-9239-c38ece572d01

STIX ID: report--5dae5306-c070-5851-9239-c38ece572d01

Feed Name: GBHackers

Threat Score
60/100

Date Published: 2026-03-10

Date Updated: 2026-04-22

Author: Divya

...
...

**Executive summary:** CERT/CC issues an advisory on VU#976247 describing a ZIP archive header manipulation evasion that causes AV/EDR scanners to rely on incorrect compression metadata and miss embedded malicious payloads; attackers circumvent this by using custom loaders that ignore the tampered fields to extract and execute hidden malware. Cisco is confirmed affected and organizations are advised to stop trusting declared archive metadata, enable aggressive detection modes, flag metadata inconsistencies, and contact vendors for patches.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.