New 'Zombie ZIP' technique lets malware slip past security tools
ID: 2d37a64e-7185-58f3-879e-0544194fac89
STIX ID: report--2d37a64e-7185-58f3-879e-0544194fac89
Feed Name: Bleeping Computer
Zombie ZIP is a proof-of-concept technique that forges ZIP headers (declaring Method=0/STORED while data is actually DEFLATE-compressed) so many AV/EDR engines scan compressed noise and miss embedded payloads; a researcher published samples and a loader, CERT/CC issued a bulletin and a CVE was assigned, but multiple security researchers and MITRE later disputed whether the technique qualifies as a vulnerability since archives become unusable by standard unarchivers and exploitation requires a custom loader.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
