Nested-ZIP Delivery of a Spark RAT Dropper — APT24's Supply-Chain Smuggling Trick
On 2026-08-27, the CISO Daily Digest flagged two campaigns that both ride on untrusted-file delivery: China-linked APT24 infiltrated Taiwan's advertising supply chain and planted malware on trusted news and novel (fiction) websites, turning everyday media into drive-by payload hosts; and Spark RAT was reported targeting Cambodia while abusing a vulnerable OPSWAT driver to silently disable endpoint security tooling. Both need a reliable way to get a malicious loader past perimeter scanners — and nested archives are a classic answer. Attackers bury the real payload several ZIP layers deep: a .zip that contains a .zip that contains yet another .zip before the actual file appears. Each layer adds friction for single-pass scanners and manual review, so the marker that flags the malicious content rides inside the innermost archive completely unseen by any control that never recurses. This demo reproduces the pattern safely — the innermost payload is an inert, non-executable marker (no code, no macro, no calculator, no network), so there is zero real payload and no destruction. MetaDefender Archive Engine recursively unpacks archives across every nesting level, applies deep scanning to each extracted file, and enforces configurable limits on depth and file count, so deeply hidden markers like the Spark RAT loader behind the APT24 supply-chain campaign cannot escape detection.
Attack Technique
Payload buried in nested ZIP layers (T1027.003)
MITRE ATT&CK
T1027.003 ↗Platforms
File Types
MetaDefender Capabilities
Incident Coverage
This attack technique maps to a real-world security incident — read the daily digest for details: Read the incident digest ↗