Skip to main content
← Back to Demos
Archive Abuse intermediate · 15 min

Nested-ZIP Delivery of a Spark RAT Dropper — APT24's Supply-Chain Smuggling Trick

On 2026-08-27, the CISO Daily Digest flagged two campaigns that both ride on untrusted-file delivery: China-linked APT24 infiltrated Taiwan's advertising supply chain and planted malware on trusted news and novel (fiction) websites, turning everyday media into drive-by payload hosts; and Spark RAT was reported targeting Cambodia while abusing a vulnerable OPSWAT driver to silently disable endpoint security tooling. Both need a reliable way to get a malicious loader past perimeter scanners — and nested archives are a classic answer. Attackers bury the real payload several ZIP layers deep: a .zip that contains a .zip that contains yet another .zip before the actual file appears. Each layer adds friction for single-pass scanners and manual review, so the marker that flags the malicious content rides inside the innermost archive completely unseen by any control that never recurses. This demo reproduces the pattern safely — the innermost payload is an inert, non-executable marker (no code, no macro, no calculator, no network), so there is zero real payload and no destruction. MetaDefender Archive Engine recursively unpacks archives across every nesting level, applies deep scanning to each extracted file, and enforces configurable limits on depth and file count, so deeply hidden markers like the Spark RAT loader behind the APT24 supply-chain campaign cannot escape detection.

Attack Technique

Payload buried in nested ZIP layers (T1027.003)

MITRE ATT&CK

T1027.003 ↗

Platforms

linux

File Types

.zip

MetaDefender Capabilities

Archive Engine

Incident Coverage

This attack technique maps to a real-world security incident — read the daily digest for details: Read the incident digest ↗

--- ---