Password-protected RAR hiding payload from static inspection
Microsoft recently disclosed a Photo ZIP phishing campaign targeting the hospitality industry, in which password-protected ZIP archives disguised as photo files delivered a Node.js-based backdoor that establishes WebSocket command-and-control, executes arbitrary commands, and moves laterally inside hotel reservation networks. Password-protected archives are a favored evasion trick: the encrypted container blocks static inspection, so scanners see only ciphertext, and the payload decrypts only when the victim opens it with the shared password (MITRE T1027.002). The Archive Engine handles the challenge differently - it decrypts and extracts archive contents, recursively unpacks nested files, and passes every extracted item through multi-engine scanning and content inspection. The demo uses a benign RAR protected with a known password and containing only harmless test content.
Attack Technique
Password-protected archive
MITRE ATT&CK
T1027.002 ↗Platforms
File Types
MetaDefender Capabilities
Incident Coverage
This attack technique maps to a real-world security incident — read the daily digest for details: Read the incident digest ↗