Attackers Use Malformed ZIP Archives to Evade Antivirus and EDR Tools
ID: 5dae5306-c070-5851-9239-c38ece572d01
STIX ID: report--5dae5306-c070-5851-9239-c38ece572d01
Feed Name: GBHackers
**Executive summary:** CERT/CC issues an advisory on VU#976247 describing a ZIP archive header manipulation evasion that causes AV/EDR scanners to rely on incorrect compression metadata and miss embedded malicious payloads; attackers circumvent this by using custom loaders that ignore the tampered fields to extract and execute hidden malware. Cisco is confirmed affected and organizations are advised to stop trusting declared archive metadata, enable aggressive detection modes, flag metadata inconsistencies, and contact vendors for patches.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
