logo

7-Zip MotW bypass exploited in zero-day attacks against Ukraine

ID: 4b773ccd-cdce-5a59-a4c1-a055d6933a1a

STIX ID: report--4b773ccd-cdce-5a59-a4c1-a055d6933a1a

Feed Name: Bleeping Computer

Threat Score
86/100

Date Published: 2025-02-04

Date Updated: 2026-03-27

Author: Bill Toulas

...
...

A 7‑Zip zero-day (CVE‑2025‑0411) was actively exploited by Russian-linked actors beginning in September 2024 to bypass Windows' Mark of the Web using nested/double archives, enabling SmokeLoader payload delivery via phishing to multiple Ukrainian government and private organizations; 7‑Zip issued a patch in version 24.09 (released Nov 30, 2024).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.