Cyber Attacks

Russian Cybercriminals exploit 7-Zip flaw to deploy SmokeLoader Malware

0

A recently patched security flaw in the 7-Zip archiver, tracked as CVE-2025-0411 (CVSS score: 7.0), has been actively exploited by Russian cybercrime groups to deploy the SmokeLoader malware. The flaw enables attackers to bypass Windows’ Mark-of-the-Web (MotW) protections, allowing malicious code execution under the current user’s privileges.

7-Zip addressed the vulnerability in November 2024 with version 24.09, but security researchers at Trend Micro observed its exploitation in targeted spear-phishing campaigns. Attackers used homoglyph techniques to disguise file extensions, deceiving users and the Windows OS into executing malicious payloads.

Targeted Cyber Espionage in Ukraine

The exploitation of CVE-2025-0411 is suspected to be part of a cyber espionage campaign against Ukrainian governmental and non-governmental entities, amidst the ongoing Russo-Ukrainian conflict.

MotW is a Windows security feature designed to prevent automatic execution of downloaded files by requiring further validation via Microsoft Defender SmartScreen. However, attackers circumvented these protections by double-archiving malicious payloads in 7-Zip.

Attack Chain: Phishing and SmokeLoader Deployment

Trend Micro detected initial exploitation of the flaw as a zero-day on September 25, 2024. The attack begins with phishing emails containing a specially crafted archive file. This file includes a homoglyph attack, making a ZIP archive appear as a Microsoft Word document.

These phishing emails, sent from compromised Ukrainian government and business accounts, targeted municipal agencies and businesses. The use of legitimate email accounts increased the credibility of the attacks, making recipients more likely to open the attachments.

Once opened, the ZIP archive contains an internet shortcut (.URL) file pointing to an attacker-controlled server that delivers another ZIP file. This second archive includes a SmokeLoader executable disguised as a PDF document, leading to malware deployment.

At least nine Ukrainian government entities have been affected, including the Ministry of Justice, Kyiv Public Transportation Service, Kyiv Water Supply Company, and City Council.

Recommendations for Mitigation

Given the active exploitation of CVE-2025-0411, users and organizations are urged to take the following precautions:

  • Update 7-Zip to version 24.09 or later to patch the vulnerability.
  • Implement email filtering to block phishing attempts and suspicious attachments.
  • Disable execution of files from untrusted sources to reduce risk.

Researchers noted that many targeted entities were smaller local government bodies, which often lack the cybersecurity resources of larger agencies. These organizations can serve as pivot points for attackers to infiltrate larger governmental networks.

As cyber threats continue to evolve, proactive security measures remain critical in defending against sophisticated nation-state attacks.

Image Credit : Help Net Security

Priyanka R
Cyber Security Enthusiast, Security Blogger, Technical Editor, Author at Cyber Safe News

Authorities seize Domains linked to HeartSender Cybercrime Group

Previous article

Brute Force Attack hits VPN devices with 2.8M IPs

Next article

You may also like

Comments

Leave a reply

Your email address will not be published. Required fields are marked *