7-Zip MotW bypass exploited in zero-day attacks against Ukraine
ID: 4b773ccd-cdce-5a59-a4c1-a055d6933a1a
STIX ID: report--4b773ccd-cdce-5a59-a4c1-a055d6933a1a
Feed Name: Bleeping Computer
Threat Score
A 7‑Zip zero-day (CVE‑2025‑0411) was actively exploited by Russian-linked actors beginning in September 2024 to bypass Windows' Mark of the Web using nested/double archives, enabling SmokeLoader payload delivery via phishing to multiple Ukrainian government and private organizations; 7‑Zip issued a patch in version 24.09 (released Nov 30, 2024).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
