logo

Hackers now use ZIP file concatenation to evade detection

ID: 50217ad4-8c9a-5819-ba54-6dcc2e9719df

STIX ID: report--50217ad4-8c9a-5819-ba54-6dcc2e9719df

Feed Name: Bleeping Computer

Threat Score
60/100

Date Published: 2024-11-10

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Perception Point discovered a phishing campaign that hid a Windows trojan inside concatenated ZIP archives—multiple ZIP files appended together so some archive tools show only benign contents while others reveal the malicious executable. The report explains how 7zip, WinRAR, and Windows File Explorer differ in handling concatenated ZIPs, demonstrates the evasion implications, and recommends defenses like security solutions with recursive unpacking and stricter email/archive filtering.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.