Blogs

Phishing by Compressed (ZIP) Files

Dec 18, 2024 1 min read
Phishing by Compressed (ZIP) Files

The use of compressed files has become widespread in a new way to bypass security systems, which is by merging compressed files together into one file.

The hacker creates two compressed files; one containing a harmless file, the other containing a malicious file, and then merges them into one file by adding the second file to the end of the first file.

This method takes advantage of how decompression programs read compressed files; some programs, such as antivirus and 7-Zip, only read the first file, while a program like WinRar reads the second file.

This allows the hacker to bypass the security system, as the protection system or software analyst using 7-Zip does not see the malicious file, while the end user using WinRar extracts and runs the malicious file.

 


Leave a Reply

Your email address will not be published. Required fields are marked *

Join us at Libya Tech Forum 2026 at Nile Ritz-Carlton Hotel, from 1-3 July, Booth E17. See you there!