Microsoft is searching within your secure folders for malware, even if you have a password

Illustration of a laptop with a magnifying glass exposing a beetle on-screen
(Image credit: Shutterstock / Kanoktuch)

Microsoft has reportedly started scanning password-protected .ZIP archives for malware, and not everyone is happy about the decision.

Ars Technica reported several users on Mastodon, including cybersecurity researchers, confirmed that Microsoft’s antivirus program had started scanning .ZIP archives for malicious content, even those protected by a password. 

Password-protected .ZIP archives are one of the most popular tactics among cybercriminals looking to deploy malware via email, as email security services rarely flag them.

"Nosy practices"

The publication claims that the practice was “well-known to some people”, but came as a surprise to others. Cybersecurity researcher Andrew Brandt, for example, wasn’t too thrilled about the idea, as it made it difficult for him to share malware with his fellow researchers through SharePoint.

"While I totally understand doing this for anyone other than a malware analyst, this kind of nosy, get-inside-your-business way of handling this is going to become a big problem for people like me who need to send their colleagues malware samples,” Brandt wrote. “The available space to do this just keeps shrinking and it will impact the ability of malware researchers to do their jobs.”

Another researcher, Kevin Beaumont, said the company scans files not just stored in SharePoint, but everywhere in its Microsoft 365 cloud services, adding that there are multiple methods of peeking into password-protected archives. One way, it seems, is to scan the contents of the email itself, for potential passwords. Sometimes, people mailing .ZIP archives to one another will share the password in the body of the email.

“If you mail yourself something and type something like 'ZIP password is Soph0s', ZIP up EICAR and ZIP password it with Soph0s, it'll find (the) password, extract and find,” he wrote.

While this might come as a surprise to some people, Ars Technica reminds that password-protected .ZIP files “provide minimal assurance” that an unauthorized third-party will read the contents. “The default means for encrypting zip files in Windows, is trivial to override. A more dependable way is to use an AES-256 encryptor built into many archive programs when creating 7z files,” the report concludes.

Via: Ars Technica

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
email
A Windows filetype update may have complicated cyber threat detection efforts
A computer being guarded by cybersecurity.
Worrying Windows security issue patched by 7-Zip, so patch now
OneDrive on a Laptop
Microsoft One Drive for Business might not be storing your data as securely as you might hope
A digital representation of a lock
Security experts are being targeted with fake malware discoveries
A padlock resting on a keyboard.
Massive botnet is targeting Microsoft 365 accounts across the world
A fish hook is lying across a computer keyboard, representing a phishing attack on a computer system
Microsoft 365 accounts are under attack from new malware spoofing popular work apps
Latest in Security
Hacker silhouette working on a laptop with North Korean flag on the background
North Korea unveils new military unit targeting AI attacks
An image of network security icons for a network encircling a digital blue earth.
US government warns agencies to make sure their backups are safe from NAKIVO security issue
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
This top WordPress plugin could be hiding a worrying security flaw, so be on your guard
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
Veeam urges users to patch security issues which could allow backup hacks
UK Prime Minister Sir Kier Starmer
The UK releases timeline for migration to post-quantum cryptography
Representational image depecting cybersecurity protection
Cisco smart licensing system sees critical security flaws exploited
Latest in News
Ray-Ban Meta Smart Glasses
Samsung's rumored smart specs may be launching before the end of 2025
Apple iPhone 16 Review
The latest iPhone 18 leak hints at a major chipset upgrade for all four models
Quordle on a smartphone held in a hand
Quordle hints and answers for Monday, March 24 (game #1155)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Monday, March 24 (game #386)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Monday, March 24 (game #652)
Quordle on a smartphone held in a hand
Quordle hints and answers for Sunday, March 23 (game #1154)