Russian Cybercrime Groups Exploiting 7-Zip Flaw to Bypass Windows MotW Protections

The SmokeLoader virus was distributed in the open by taking advantage of a recently fixed security flaw in the 7-Zip archiver program.

The vulnerability, CVE-2025-0411 (CVSS score: 7.0), enables remote attackers to run arbitrary code within the current user’s context and get around mark-of-the-web (MotW) protections. In November 2024, 7-Zip released version 24.09 to address it.

According to Peter Girnus, a security researcher at Trend Micro, Russian cybercriminal organizations actively took use of the vulnerability through spear-phishing campaigns, spoofing document extensions with homoglyph attacks to fool users and the Windows OS into running malicious files read more about Russian Cybercrime Groups Exploiting 7-Zip Flaw to Bypass Windows MotW Protections.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *