OpenSUpdater Hides in Recompiled 7zip SFX, Evading Analysts
Reported 24 Sep 2026 by otx · Severity: medium
Threat actors are recompiling open source software, specifically the 7zip self-extracting archive stub, to embed a reflective loader that evades detection. The malicious code is inserted into the ExtractArchive function of the 7zip SFX module, making it difficult for analysts to