Threat actors are hiding an OpenSUpdater reflective loader inside a recompiled 7-Zip self-extracting archive (SFX) module. The installer contains a genuine foobar2000 setup file, but the malicious code runs from the extraction stub itself a component analysts may overlook when the extracted files appear clean. Recent samples are detected as... Weiterlesen
Intelligence View
⚡ tsecurity.de Intelligence
OpenSUpdater Malware Hides Reflective Loader Inside Recompiled 7-Zip SFX to Evade Detection
Threat actors are hiding an OpenSUpdater reflective loader inside a recompiled 7-Zip self-extracting archive (SFX) module. The installer contains a genuine foobar2000 setup file, but the malicious code runs from the extraction stub itself…
Reagiere als Erste:r — dein Feedback zählt!