• About Us
King of Computer Media
  • Home
  • Tech News
  • AI News
  • Apps & Tutorials
  • Mobile & Telecom
  • Lifestyle
  • About Us
No Result
View All Result
  • Home
  • Tech News
  • AI News
  • Apps & Tutorials
  • Mobile & Telecom
  • Lifestyle
  • About Us
No Result
View All Result
King of Computer Media
No Result
View All Result

Home - Anti-Virus Software and Internet Security - No surprise! These file types are most commonly used by hackers to hide malware

No surprise! These file types are most commonly used by hackers to hide malware

Claire by Claire
December 2, 2022 - Updated on August 4, 2026
in Anti-Virus Software and Internet Security

The Internet plays a very important role in modern people’s lives, but wherever there are people, there are rivers and lakes, and various network attacks that follow are growing on the Internet, bringing a lot of trouble and threats to everyone. ZIP and RAR have surpassed Office files as the most common file types used by cybercriminals to deliver malware, according to an analysis of real-world cyber attacks and data collected on millions of computers.

These file types are most commonly used by hackers to hide malware

according to HP Wolf Security Customer Data Analysis, between July and September 2022, 42% of malware attacked in file formats, including ZIP and RAR. This means that cyberattacks that attempt to exploit compressed formats such as ZIP and RAR are more common than those that attempt to exploit Microsoft Office files (Microsoft Word, Microsoft Excel, etc.). This is the first time in more than three years that compressed file formats have surpassed Office files.

Hiding malicious files through encryption and compression provides attackers with a way to bypass many security protections. Encrypted and compressed malware can evade network proxies, sandboxes, and email scanners, making attacks difficult to detect, especially when combined with HTML technology. In many cases, attackers use phishing emails that look like they come from well-known brands and online service providers to try to trick users into opening and running malicious ZIP and RAR files.

According to analysis by HP Wolf Security, one of the most notorious malware campaigns now relying on ZIP and malicious HTML files is Qakbot, a malware family used not only to steal data but also as a backdoor to deploy ransomware. Qakbot resurfaced in September, sending malicious messages via email claiming to be related to online documents that needed to be opened. If the file is run, it downloads and executes the payload in the form of a dynamic link library, which is then launched using legitimate but commonly abused tools in Windows.

Soon after, cybercriminals distributing IcedID, a malware installed to enable hands-on, human-operated ransomware attacks, began using a nearly identical template to Qakbot to abuse zip files to trick victims into downloading the malware. Both campaigns work hard to ensure that emails and fake HTML pages look legitimate to deceive as many victims as possible. This involves using a malicious HTML file in an email disguised as a PDF file, which when run displays a fake online file viewer that can decode the ZIP archive and infect the user with malware if they download it.

There are also ransomware groups that abuse ZIP and RAR files in this way. According to HP Wolf Security, the Magniber ransomware group is targeting home users in its campaign by encrypting files and demanding a $2,500 ransom from victims. In this case, the infection began with a download from an attacker-controlled website, which asked users to download a ZIP archive containing JavaScript that claimed to be an important antivirus or Windows 10 software update. If you trust it and run it, it will download and install ransomware.

Prior to the latest Magniber campaign, ransomware was delivered via MSI and EXE files, but like other cybercriminal groups, they have noticed successful infections by delivering payloads hidden in compressed files. Cybercriminals are constantly changing their attack methods, and phishing remains one of the key methods for delivering malware, as it is often difficult to detect whether an email or file is harmless. I would like to remind everyone to be cautious when seeing requests to open links and download attachments, especially when they come from unexpected or unknown sources.

 

 

Source: KOCPC Chinese

Tags: blackmailcompressed filecyber threatsHPInternet securitymalwareZIP

Recent Posts

  • The Xiaomi Pad 8S Pro has passed network access certification and will debut with the self-developed XRING O3 chip.
  • The entire Google Pixel 11 lineup has been leaked! Official promotional renders of the Pixel 11 Pro XL have also surfaced
  • Are Chinese phone battery capacities falsely labeled? A brief look at the “capacity locking” phenomenon in Chinese silicon-carbon batteries.
  • NCC is leaderless, recklessly sending out national-level alert messages!?
  • What does “QR” in QR Code mean?

Recent Comments

No comments to show.
  • About Us

We welcome partnership inquiries and product review opportunities from smartphone manufacturers, iPhone accessory brands, and app developers.koc kocpc.com.tw|Privacy Policy |Hosting & Maintenance: Fast Line Taiwan, A-Chang Digital Technology

No Result
View All Result
  • Home
  • Tech News
  • AI News
  • Apps & Tutorials
  • Mobile & Telecom
  • Lifestyle
  • About Us

We welcome partnership inquiries and product review opportunities from smartphone manufacturers, iPhone accessory brands, and app developers.koc kocpc.com.tw|Privacy Policy |Hosting & Maintenance: Fast Line Taiwan, A-Chang Digital Technology