logo

Flexible Structure of Zip Archives Exploited to Hide Malware Undetected

ID: f89ca690-903a-5651-a709-159af5f4eca2

STIX ID: report--f89ca690-903a-5651-a709-159af5f4eca2

Feed Name: Dark Reading

Threat Score
70/100

Date Published: 2024-11-11

Date Updated: 2026-04-21

Author: Elizabeth Montalbano, Contributing Writer

...
...

Perception Point researchers observed phishing emails delivering concatenated ZIP files that conceal a variant of the SmokeLoader trojan; the technique abuses how different archive readers (7-Zip, Windows Explorer, WinRAR) parse concatenated archives to hide malicious payloads from some analysis tools. The report details the attack flow (malicious attachment masquerading as a shipping document), the parsing differences that enable evasion, and recommends recursive extraction and advanced detection to reveal hidden payloads.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.