ZIP files are being used to bypass security gateways

(Image credit: Shutterstock)

Security researchers at Trustwave have discovered a new phishing campaign that utilized a specially crafted ZIP file, designed to bypass secure email gateways, to distribute the NanoCore RAT.

Users are targeted through a spam email pretending to be shipping information from an Export Operation Specialist of USCO Logistics. Attached to the email is a ZIP archive that has a file size which is greater than its uncompressed content.

In a new report, Trustwave explained why the size of the ZIP raised suspicions among its researchers, saying:

"The attachment “SHIPPING_MX00034900_PL_INV_pdf.zip“ makes this message stand out. The ZIP file had a file size significantly greater than that of its uncompressed content. Typically, the size of the ZIP file should be less than the uncompressed content or, in some cases, ZIP files will grow larger than the original files by a reasonable number of bytes."

Suspicious ZIP files

In addition to a special structure that contains the compressed data and information about the compressed files, each ZIP archive also contains a single End of Central Directory (EOCD) record that is used to indicate the end of the archive structure.

However, when Trustwave researchers examined the ZIP file attached to the spam email, they found that the ZIP archive contained two distinct archive structures that both had their own EOCD record. A ZIP archive should have only one EOCD record and this shows that the ZIP file created by the attackers was altered to contain two archive structures.

The first ZIP structure acts as a decoy and contains a harmless image file called order.jpg. The second ZIP structure on the other hand contained an executable file which contained the NanoCore Remote Access Trojan (RAT). Trustwave then determined that the attackers created this specially crafted ZIP archive in an effort to bypass secure email gateways.

When attempting to open the archive using several file extraction programs, the researchers discovered that the archive was treated differently on a program by program basis. While Windows built-in ZIP extractor said the file was invalid and wouldn't extract it, Trustwave discovered that certain versions of PowerArchiver, WinRar and 7-Zip were able to properly extract the NanoCore executable.

The technique used by the attackers could allow them to deliver malicious payloads that are able to bypass email scanners, but due to the way file extraction programs work, less users would be infected than they initially intended.

  • Protect your devices from the latest cyber threats with the best antivirus software

Via Bleeping Computer

Anthony Spadafora

After working with the TechRadar Pro team for the last several years, Anthony is now the security and networking editor at Tom’s Guide where he covers everything from data breaches and ransomware gangs to the best way to cover your whole home or business with Wi-Fi. When not writing, you can find him tinkering with PCs and game consoles, managing cables and upgrading his smart home. 

Latest in Security
Data Breach
Thousands of healthcare records exposed online, including private patient information
China
Juniper patches security flaws which could have let hackers take over your router
Representational image depecting cybersecurity protection
GitLab has patched a host of worrying security issues
Ai tech, businessman show virtual graphic Global Internet connect Chatgpt Chat with AI, Artificial Intelligence.
AI agents can be hijacked to write and send phishing attacks
China
Volt Typhoon threat group had access to American utility networks for the best part of a year
Abstract image of cyber security in action.
MassJacker malware targets those looking for pirated software
Latest in News
Apple iPhone 16 Pro HANDS ON
Leaked iPhone 17 dummy units may have given us our best look yet at all four models
A super close up image of the Google Gemini app in the Play Store
It's official: Google Assistant will be retired for phones this year, with Gemini taking over
Quordle on a smartphone held in a hand
Quordle hints and answers for Sunday, March 16 (game #1147)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Sunday, March 16 (game #378)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Sunday, March 16 (game #644)
Three iPhone 16 handsets on show
Apple could launch an iPhone 17 Ultra this year – but we've heard these rumors before