OpenSUpdater Malware Hides Reflective Loader Inside Recompiled 7-Zip SFX Installers

OpenSUpdater Malware Hides Reflective Loader Inside (TL-2026-2767), also tracked as OpenSUpdater, is a high-severity malware campaign, first published 2026-09-29. It has no confirmed attribution, affects Microsoft Windows, maps to 11 MITRE ATT&CK techniques (T1027, T1027.001, T1027.009), and is covered by 9 detection rules and 17 indicators of compromise.

Key facts for TL-2026-2767

Threat ID
TL-2026-2767
Also known as
OpenSUpdater, Snackarcin (Microsoft detection name on related samples)
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
2026-09-29
Last reviewed
2026-09-29
Attribution confidence
LOW
Motivation
FINANCIAL
Target sectors
consumer, general
Target regions
Global
Detection rules
9
Indicators of compromise
17

Malware and tooling in OpenSUpdater Malware Hides Reflective Loader Inside

Malware and tooling: OpenSUpdater, Snackarcin, 7-Zip SFX (recompiled), NSIS EmbedHtml plugin (modified), cURL (statically compiled)

OpenSUpdater operators are hiding a reflective loader inside the decompression stub of recompiled 7-Zip self-extracting archives (and a modified NSIS EmbedHtml plugin), wrapping a genuine foobar2000 installer and signing the result as 'Animated Productions, LLC'. The loader beacons to C2, downloads two DLLs and an encrypted blob with a statically compiled cURL, and runs the final payload in memory via a cx1/cx2/cx3 DLL chain.

How OpenSUpdater Malware Hides Reflective Loader Inside works

G DATA (published 2026-09-24) documents a new evolution of the OpenSUpdater family, an unwanted-software / adware-downloader family first publicly documented by Google's Threat Analysis Group (TAG) on 2021-09-23 for shipping intentionally malformed Authenticode signatures since mid-August 2021. Instead of hiding malicious code in the bundled setup.exe or the SFX configuration, the operators recompile 7-Zip's SFX setup module and insert the loader into the ExtractArchive() routine (call at offset 0x421400 in the first sample; the legitimate routine lives in CPP/7zip/Bundles/SFXSetup/ExtractEngine.cpp), immediately before the progress bar is initialized. Analysts who triage SFX archives by inspecting the embedded executable and configuration therefore miss the malicious path, which lives in what appears to be a trusted, standard 7-Zip component.

The loader performs three functions: (1) it retrieves C2 URLs through an obfuscated routine and registers with the C2 using a distinct magic byte sequence; (2) it uses a statically compiled cURL to download two DLLs and an encrypted blob from the C2; and (3) it executes the payload in memory. The first DLL's export cx1 is invoked, the second DLL's export cx2 decrypts the blob, and the resulting DLL is reflectively mapped into memory and its export cx3 executed. G DATA describes the final DLL as the presumed payload; the analyst states no DLLs were obtained from the C2 at the time of analysis, so the payload's function is unknown.

The analyzed samples package a genuine foobar2000 audio-player installer (setup.exe) as cover (an installer-within-installer structure) and carry a valid signature from 'Animated Productions, LLC', a purported game-application developer, producing a publisher-to-payload mismatch. The certificate data is bloated with repeated byte patterns (0xB8 and 0x84) amounting to roughly 2.6% of file size, which changes the file hash per build without invalidating the signature and hinders hash-based detection. Samples also carry random version-information strings. A second variant modifies the NSIS EmbedHtml plugin, placing the loader in EmbedHtml::GetUrl() so that it activates only when called with an empty-string argument; in that variant the C2 address is recovered from a compressed blob inside the NSIS script. Two C2 domains were identified: codeonicinc[.]com (both 7-Zip-variant samples) and setupsoftwarecenter[.]com (the NSIS-variant sample). Detection names: ESET 'OpenSUpdater' and Microsoft 'Snackarcin' on related samples.

Attribution and scale are unestablished: no CVE, named threat actor, or victim count was disclosed. Google TAG's and BleepingComputer's 2021 reporting characterized OpenSUpdater as adware/riskware that injects ads and installs other unwanted programs, with targets mostly in the US seeking game cracks and other grey-area software. The 2021 TAG technique was a signature-algorithm parameters element with an End-of-Content marker in place of a NULL tag (bytes 30 0D 06 09 2A 86 48 86 F7 0D 01 01 0B 00 00), accepted by Windows but rejected by OpenSSL-based parsers. A link between that reporting and the 2026 operators' identity is not established beyond the shared family name. BeaconBeagle config search for setupsoftwarecenter.com returned no matches.

MITRE ATT&CK techniques used in TL-2026-2767

Defense Evasion

T1027 Obfuscated Files or Information; T1027.001 Obfuscated Files or Information: Binary Padding; T1027.009 Obfuscated Files or Information: Embedded Payloads; T1027.013 Obfuscated Files or Information: Encrypted/Encoded File; T1036 Masquerading; T1036.001 Masquerading: Invalid Code Signature; T1140 Deobfuscate/Decode Files or Information; T1620 Reflective Code Loading

Command and Control

T1071.001 Application Layer Protocol: Web Protocols

Execution

T1204.002 User Execution: Malicious File

defense-impairment

T1553.002 Subvert Trust Controls: Code Signing

Affected products and versions in OpenSUpdater Malware Hides Reflective Loader Inside

  • Microsoft — Windows
    Vulnerable versions: Windows endpoints executing the trojanized SFX/NSIS installers

Remediation for OpenSUpdater Malware Hides Reflective Loader Inside

Immediate actions

  • Block and alert on outbound connections to codeonicinc.com and setupsoftwarecenter.com
  • Hunt for the three published SHA-256 hashes and for setup.exe / foobar2000 installers signed by 'Animated Productions, LLC'
  • Quarantine hosts where an SFX/NSIS installer spawned a process that then made HTTPS downloads and loaded unbacked (reflectively mapped) DLLs

Workarounds

  • Enforce application control so that only approved publishers' installers can execute
  • Egress-filter newly registered or uncategorized domains from user workstations

Longer-term hardening

  • Do not treat a valid code signature or a legitimate-looking extracted installer as proof of safety; analyze the SFX stub and bundled NSIS plugin code
  • Diff SFX stubs and NSIS plugins against upstream builds to catch recompiled components
  • Detect certificate anomalies such as oversized or padded signature blocks, malformed signature-algorithm structures, and publisher-to-product mismatches
  • Flag installer-within-installer configurations and anomalous or random version-information metadata
  • Deploy EDR with behavioral coverage for reflective code loading and in-memory DLL mapping
  • Restrict installation of software from untrusted sources through application allow-listing

Timeline of OpenSUpdater Malware Hides Reflective Loader Inside

  • Google TAG observes OpenSUpdater samples carrying intentionally malformed signatures since mid-August 2021 (exact day not stated; mid-month used).
  • BleepingComputer covers the TAG finding, describing OpenSUpdater as adware/riskware that injects ads and installs other unwanted programs.
  • Google TAG publishes 'Financially motivated actor breaks certificate parsing to avoid detection' (researcher Neel Mehta), documenting the family's End-of-Content signature trick and two sample hashes; targets mostly US users seeking game cracks.
  • OffSeq Threat Radar ingests the G DATA report and lists the three SHA-256 hashes, two C2 domains and mapped ATT&CK techniques.
  • G DATA publishes 'OpenSUpdater Hides in Recompiled 7zip SFX, Evading Analysts', detailing the loader in the recompiled 7-Zip SFX stub (ExtractArchive at 0x421400) and the NSIS EmbedHtml::GetUrl variant, with three SHA-256 hashes and two C2 domains; the analyst obtained no DLLs from the C2.
  • Threadlinqs opens tracking record TL-2026-2767 for the OpenSUpdater 7-Zip SFX loader campaign.
  • GBHackers publishes coverage of the G DATA analysis, highlighting the reflective loader, cx1/cx2/cx3 chain and Animated Productions, LLC signature.
  • CyberPress publishes coverage naming ESET (OpenSUpdater) and Microsoft (Snackarcin) detections and repeating the IOCs.

Sources cited for OpenSUpdater Malware Hides Reflective Loader Inside

More in malware

Detection coverage for TL-2026-2767

As of 2026-09-29, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2767 across Splunk SPL, Microsoft KQL and Sigma, covering 17 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat weather, live.

Every square is one real report, mapped to MITRE ATT&CK and shipped with Splunk SPL, Microsoft KQL and Sigma detections you can copy.

Every threat in the corpus, newest first.

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats