OpenSUpdater Malware Hid Inside 7-Zip Installers
Threat actors have modified the decompression stub of popular 7-Zip software to covertly execute malicious code.
Updated on Sept. 29, 2026 in Cybersecurity

Live Poll
Do you trust the security of files downloaded from third-party websites?
Security researchers have identified a new campaign where the OpenSUpdater malware is distributed via recompiled 7-Zip self-extracting archive components. This method allows the malicious payload to bypass standard security detection protocols.
Why it matters
By subverting legitimate compression utilities, attackers can execute malicious code that evades traditional triage and signature-based identification. This shift highlights a persistent trend of embedding threats within trusted open-source tools to maintain persistence.
The attackers utilize a reflective loader to execute code directly from memory after modifying the decompression stub. This approach hides the malicious payload within standard archive components, contrasting with typical binary delivery methods.
The players
OpenSUpdater
A strain of malware identified in security reports that employs reflective loading techniques to maintain persistence on infected systems.
7-Zip
An open-source file archiver tool widely used for data compression and file management across multiple operating systems.
The details
The attack mechanism involves re-engineering the self-extracting archive structure used by 7-Zip. By modifying the decompression stub—the code block responsible for initiating file extraction—operators force the system to trigger a reflective loader. A reflective loader is a technique that loads a library or executable into a process's memory space without relying on the operating system's standard loading mechanisms, effectively bypassing file-based security scanners.
Timeline
September 29, 2026: Security researchers published the analysis of OpenSUpdater distribution techniques.
The Tech Race
This campaign follows the established pattern of supply chain compromises where adversaries weaponize trusted, widely-distributed software utilities to bypass standard security heuristics. It echoes the 2020 SolarWinds supply chain attack by demonstrating how subverting the installation process of essential infrastructure software allows for persistent, high-stealth access.
Users should verify the integrity and source of 7-Zip installers by ensuring they are downloaded only from the official project website. Systems that appear sluggish or exhibit unexpected behavior after extracting files should be scanned with updated endpoint protection software.
The takeaway
Adversaries are increasingly exploiting the trust placed in ubiquitous open-source utilities to mask their activity. Users should prioritize source verification and maintain updated behavioral analysis tools to detect memory-based threats that do not rely on traditional file signatures.
Further reading
For broader context on how threat actors subvert software supply chains, visit the Cybersecurity section.
Live Poll
Do you trust the security of files downloaded from third-party websites?






