thumbnail

Hackers Use Specially Compressed ZIP Files to Spread Malware

NK

NexKraft Team

2024-11-17


A cybersecurity company, Perception Point, recently uncovered this technique while analyzing a phishing attack. Hackers sent phishing emails disguised as fake shipping notifications with an attached ZIP file. When the ZIP file was opened, the hidden malware activated, executing malicious operations on the victim’s device.

How This ZIP File Technique Works

Unlike conventional ZIP files, these malicious archives employ a unique structure. Hackers create several smaller ZIP files, one of which contains the malware, while the others house seemingly harmless data. These smaller ZIP files are then combined into a single archive. While the file appears ordinary to the naked eye, its layered structure confuses many security tools, allowing the malware to evade detection.

Hackers exploit the limitations of various unzipping tools to make this method effective. For example:

  • 7-Zip analyzes only the first ZIP file, often failing to detect hidden malware.
  • WinRAR, on the other hand, fully extracts all files, improving malware detection capabilities.
  • Windows File Explorer does not always accurately extract complex ZIP structures, giving hackers an opportunity to disguise malware.

Tips to Stay Protected

To defend against this type of malware attack, follow these precautions:

  1. Use Advanced Security Software: Opt for tools capable of analyzing every layer of a ZIP archive. This increases the chances of detecting concealed malware.
  2. Be Vigilant with Emails: Avoid opening suspicious emails or attachments, especially ZIP files, without verifying their authenticity.
  3. Filter File Formats: Implement file format filtering in your security settings to block suspicious archive files from entering your system.

With hackers constantly evolving their tactics, staying informed and adopting robust security measures is essential to ensure data safety and prevent breaches.

Source: BleepingComputer.com

100+ companies have uplifted their business with NexKraft. Tell us about your project.

Chat to us

Our friendly team is here to help.

hello@nexkraft.com
Call us

Mon-Fri from 10am to 7pm.

+8801817020000
+8801817030000
GMT+6
+19312199992
GMT -5
+447946011952
GMT +01:00
+60321488888
GMT+8
+919880162977
GMT +05:30
Visit us

Come say hello at our office HQ.

50 Lake Circus Road Kalabagan, Dhanmondi Dhaka-1205
31140 Pecan Creek Dr, Brookshire, TX 77423
1 Compass Point, 5 Grenade Street, London, E14 8HL United Kingdom
Apt 151-1, Tgkt 1, Wisma nutiara puchong, jalan puchong 58200 Kuala Lumpur
521, 4th C Cross , 2nd Block HRBR Layout, Bangalore - 560043, Karnataka, India
Follow Us on

CONTACT

We are ready to help you bring your idea to life. Fill out the form and we will be in touch shortly.