Secure Bulletin Navigating the cyber sea with knowledge
Home > Articolo > Trojanized 7-Zip Installers Hide Downloaders Inside Extraction Code
Trojanized 7-Zip Installers Hide Downloaders Inside Extraction Code
Read Time:3 Minute, 17 Second

Malware operators are modifying the extraction component of 7-Zip self-extracting archives so that malicious code runs before a genuine bundled application is installed. The technique makes a package look ordinary both to its intended victim and to analysts who focus on the files inside the archive. Researchers linked the samples to OpenSUpdater, which Microsoft also tracks as Snackarcin.

The observed archives contained a legitimate foobar2000 audio-player installer. That working program strengthens the deception: the expected setup starts and may complete normally, while the altered wrapper quietly contacts attacker-controlled infrastructure. The finding does not indicate a vulnerability in standard 7-Zip archives. The attackers rebuilt open-source installer code and inserted their own loader.

The harmful behavior runs before the decoy

A typical self-extracting archive consists of an extraction program, configuration data and packaged files. Analysts commonly inspect the configuration and the program that launches after extraction. In this campaign, those obvious areas point toward the legitimate installer, while the malicious call is embedded inside the extraction routine itself.

G Data Software researchers found the added loader call immediately before the installation progress display begins. The modified component retains the shape, strings and imported functions of an ordinary 7-Zip stub. A quick static review can therefore dismiss it as standard packaging code, particularly when the visible application runs as promised.

The packages also carried a valid digital signature issued to Animated Productions, LLC, a publisher whose apparent game-app business did not align with the included audio software. Researchers observed repeated padding bytes in the certificate and unusual version information. A valid signature confirms that a file has not changed since signing; it does not establish that the signer is trustworthy or that the program is benign.

A staged downloader leads to an unknown payload

The hidden loader decodes a server address, registers with it using a distinctive byte pattern and downloads two DLL components plus an encrypted data blob. It invokes one function in the first DLL, uses another in the second to decrypt the blob, loads the recovered DLL into memory and calls a function believed to start the final payload.

Researchers could not retrieve those later components, so the final objective remains unconfirmed. The evidence also does not establish infection counts or identify a specific delivery campaign. Those limits are important: the samples demonstrate a capable evasion and delivery method, but not the scale or ultimate impact of its use.

A related NSIS installer variant used the same broad idea. Attackers modified an open-source plugin so the loader activated only when a particular function received an empty string. Across both formats, the recurring pattern was a real installer nested within another installer, questionable but valid signing, and malicious logic placed in code reviewers may assume is standard.

How defenders can inspect suspicious installers

  • Analyze the self-extracting stub as executable code instead of limiting review to its configuration and embedded files.
  • Compare extraction components with known-good upstream builds to identify inserted calls or altered control flow.
  • Check whether the signing identity has a plausible relationship to the bundled product and investigate certificate anomalies.
  • Monitor installers for network connections before the expected child setup program begins.
  • Escalate nested installers, inconsistent version metadata and unusually padded certificates for deeper analysis.

Application allowlisting policies should avoid treating any valid signature as sufficient proof of safety. Detection engineering can also look for outbound connections from temporary extraction processes and memory-loaded DLLs that do not appear on disk. Sandboxes should allow enough time and network access to observe behavior that starts just before or during a visible installation.

The campaign is a useful reminder that open-source packaging components can be repurposed by attackers without compromising the upstream project. Defenders need to evaluate the complete execution chain, including code that prepares the files users expect to see. G Data Software’s analysis and the known indicators were reported by Cyber Security News.

Share: Twitter  |  Facebook  |  LinkedIn
Join the discussion

This is a blog in the Fediverse: you can find this article everywhere with @blog@securebulletin.com and every comment/answer will appear here.

If you want to comment on Trojanized 7-Zip Installers Hide Downloaders Inside Extraction Code, use the discussion on Forum.

>> forum community

Comments

Leave a Reply