OpenSUpdater Hides in Recompiled 7zip SFX, Evading Analysts
Threat actors are recompiling open source software, specifically the 7zip self-extracting archive stub, to embed a reflective loader that evades detection. The malicious code is inserted into the ExtractArchive function of the 7zip SFX module, making it difficult for analysts to identify since they typically focus on configuration files and embedded executables rather than the decompression stub itself. Samples are validly signed by Animated Productions, LLC and contain legitimate installers like foobar2000. The loader beacons to C2 servers, downloads DLLs, and reflectively loads encrypted payloads. Variants also abuse other open source libraries like the NSIS plugin EmbedHtml. Files feature bloated certificates and suspicious characteristics including installers wrapped within installers, requiring persistent analysis to uncover the hidden malicious functionality.
AI Analysis
Technical Summary
This malware campaign involves threat actors recompiling the 7zip self-extracting archive stub to embed a reflective loader within the ExtractArchive function, enabling evasion of traditional detection methods that focus on configuration files and embedded executables. The malicious samples are validly code-signed by Animated Productions, LLC and often bundle legitimate installers such as foobar2000. The reflective loader establishes beacon communications to command and control servers, downloads DLLs, and reflectively loads encrypted payloads. Variants also exploit other open source components like the NSIS EmbedHtml plugin. The use of bloated certificates and installers wrapped within installers complicates detection and analysis, requiring sustained investigative efforts to uncover the concealed malicious functionality.
Potential Impact
The threat enables stealthy execution of malicious payloads by embedding them within legitimate-looking installers and using reflective loading techniques to evade detection. The valid code signing and use of legitimate software installers increase the likelihood of successful delivery and execution. The malware's ability to beacon to C2 servers and download additional payloads poses risks of further compromise and persistence on affected systems.
Mitigation Recommendations
No official patch or fix is available as this is a malware technique rather than a software vulnerability. Detection requires enhanced analysis focusing on the decompression stub of 7zip SFX modules, not just configuration files or embedded executables. Analysts should be aware of code signing abuse and certificate bloating as indicators. Persistent and in-depth inspection of installer chains and monitoring for suspicious beaconing behavior to known C2 domains such as codeonicinc.com and setupsoftwarecenter.com is recommended. Employing behavioral detection and sandboxing techniques may help uncover the reflective loader and encrypted payloads.
Indicators of Compromise
- domain: codeonicinc.com
- domain: setupsoftwarecenter.com
- hash: a7666e5aa3c6ecae0295caa7c3f49714eb561d6e1be6807cf1020b79f1902cd0
- hash: ba38916e82c47cff6de71791f179ce762e640e2975e40d6a1803d16ff591b752
- hash: e99a053b9d6a414256177e1529417f85867d6ed355f6009300d626f63429753c
OpenSUpdater Hides in Recompiled 7zip SFX, Evading Analysts
Description
Threat actors are recompiling open source software, specifically the 7zip self-extracting archive stub, to embed a reflective loader that evades detection. The malicious code is inserted into the ExtractArchive function of the 7zip SFX module, making it difficult for analysts to identify since they typically focus on configuration files and embedded executables rather than the decompression stub itself. Samples are validly signed by Animated Productions, LLC and contain legitimate installers like foobar2000. The loader beacons to C2 servers, downloads DLLs, and reflectively loads encrypted payloads. Variants also abuse other open source libraries like the NSIS plugin EmbedHtml. Files feature bloated certificates and suspicious characteristics including installers wrapped within installers, requiring persistent analysis to uncover the hidden malicious functionality.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This malware campaign involves threat actors recompiling the 7zip self-extracting archive stub to embed a reflective loader within the ExtractArchive function, enabling evasion of traditional detection methods that focus on configuration files and embedded executables. The malicious samples are validly code-signed by Animated Productions, LLC and often bundle legitimate installers such as foobar2000. The reflective loader establishes beacon communications to command and control servers, downloads DLLs, and reflectively loads encrypted payloads. Variants also exploit other open source components like the NSIS EmbedHtml plugin. The use of bloated certificates and installers wrapped within installers complicates detection and analysis, requiring sustained investigative efforts to uncover the concealed malicious functionality.
Potential Impact
The threat enables stealthy execution of malicious payloads by embedding them within legitimate-looking installers and using reflective loading techniques to evade detection. The valid code signing and use of legitimate software installers increase the likelihood of successful delivery and execution. The malware's ability to beacon to C2 servers and download additional payloads poses risks of further compromise and persistence on affected systems.
Defensive Guidance
No official patch or fix is available as this is a malware technique rather than a software vulnerability. Detection requires enhanced analysis focusing on the decompression stub of 7zip SFX modules, not just configuration files or embedded executables. Analysts should be aware of code signing abuse and certificate bloating as indicators. Persistent and in-depth inspection of installer chains and monitoring for suspicious beaconing behavior to known C2 domains such as codeonicinc.com and setupsoftwarecenter.com is recommended. Employing behavioral detection and sandboxing techniques may help uncover the reflective loader and encrypted payloads.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://blog.gdatasoftware.com/2026/09/38490-opensupdater-evades-with-recompiled-7zip-sfx"]
- Pulse Id
- 6ab524f82bf3c05dfa346cb8
Indicators of Compromise
Domain
| Value | Description | Copy |
|---|---|---|
domaincodeonicinc.com | — | |
domainsetupsoftwarecenter.com | — |
Hash
| Value | Description | Copy |
|---|---|---|
hasha7666e5aa3c6ecae0295caa7c3f49714eb561d6e1be6807cf1020b79f1902cd0 | — | |
hashba38916e82c47cff6de71791f179ce762e640e2975e40d6a1803d16ff591b752 | — | |
hashe99a053b9d6a414256177e1529417f85867d6ed355f6009300d626f63429753c | — |
Threat ID: 6ab57e66f7a7c54106c42d66
Added to database: 09/24/2026, 19:47:50 UTC
Last enriched: 09/24/2026, 20:02:59 UTC
Last updated: 09/25/2026, 02:00:48 UTC
Views: 66
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.