HP Wolf Warns of Surge in Malware Hidden in ZIP, RAR Files

Archive files are now the most common file type used to deliver malware – eclipsing Microsoft Office files for the first time – according to HP Wolf Security’s Q3 2022 Quarterly Threat Insights Report. Forty-four percent of malware was delivered via archive files in the third quarter of 2022, 11 percent more than the previous […]

執筆者
Jeff Goldman
Jeff Goldman
Dec 1, 2022
2 minute read
eSecurity Planet のコンテンツおよび製品のおすすめは、編集上の独立性を保っています。パートナーへのリンクをクリックすると、当社が報酬を得る場合があります。 詳細を見る

Archive files are now the most common file type used to deliver malware – eclipsing Microsoft Office files for the first time – according to HP Wolf Security’s Q3 2022 Quarterly Threat Insights Report.

Forty-four percent of malware was delivered via archive files in the third quarter of 2022, 11 percent more than the previous quarter and far more than the 32 percent delivered through Office files.

The change comes as Microsoft has begun disabling Office macros by default (see Hackers Find Alternatives to Microsoft Office Macros).

HTML Smuggling

The QakBot and IceID campaigns, the report notes, trick victims with malicious HTML files masquerading as PDF documents. When victims open the files, they’re redirected to fake online document viewers masquerading as Adobe or Google Drive web pages, which tell victims to open an encrypted ZIP file allegedly containing the document.

When the victim enters a password provided to them on the web page, the ZIP file then deploys malware on the victim’s PC.

“Archives are easy to encrypt, helping threat actors to conceal malware and evade web proxies, sandboxes, or email scanners,” HP Wolf Security senior malware analyst Alex Holland said in a statement. “This makes attacks difficult to detect, especially when combined with HTML smuggling techniques.”

That’s even more of an issue when the social engineering is well thought out. “What was interesting with the QakBot and IceID campaigns was the effort put in to creating the fake pages – these campaigns were more convincing than what we’ve seen before, making it hard for people to know what files they can and can’t trust,” Holland said.

“We expect HTML smuggling design variations and brand abuse to accelerate as attackers experiment to find the most effective lures,” the report warns.

See the Top EDR Solutions

A Modular Infection Chain

A separate campaign observed in mid-September uses a modular infection chain that enables attackers to change malicious payloads and introduce new features.

The attack starts with an email containing a Microsoft Word attachment – but when the document is opened, it asks for permission to load an embedded Excel spreadsheet. If the victim gives permission, the spreadsheet then runs malicious files hosted on file sharing websites.

Advertisement

Because the malware isn’t included directly in the attachment sent to the victim, it’s also harder for security tools to detect.

“The attackers hosted different components of the malware campaign on remote web servers and used a variety of techniques to execute the payload malware,” the report states. “This modular approach benefits attackers because it enables payloads to be swapped out easily and for the execution flow to be modified mid-campaign.”

“As shown, attackers are constantly switching up techniques, making it very difficult for detection tools to spot,” Ian Pratt, global head of security for personal systems at HP, said in a statement.

See the Top Secure Email Gateway Solutions

Jeff Goldman

eSecurity Planet contributor Jeff Goldman has been a technology journalist for more than 20 years and an eSecurity Planet writer since 2009. He's also written extensively about wireless and broadband infrastructure and semiconductor engineering. He started his career at MTV, but soon decided that technology writing was a more promising path.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

TechnologyAdvice が所有・運営しています。 © 2026 TechnologyAdvice. 無断転載を禁じます

広告主に関する開示:このサイトに掲載されている製品の一部は、TechnologyAdvice が報酬を受け取っている企業のものです。この報酬は、製品がこのサイトのどこにどのように表示されるか(表示される順序など)に影響する場合があります。TechnologyAdvice は、市場で入手可能なすべての企業やすべての種類の製品を掲載しているわけではありません。