Skip to main content
← Back to Demos
Archive Abuse intermediate · 15 min

Password-protected RAR hiding payload from static inspection

Microsoft recently disclosed a Photo ZIP phishing campaign targeting the hospitality industry, in which password-protected ZIP archives disguised as photo files delivered a Node.js-based backdoor that establishes WebSocket command-and-control, executes arbitrary commands, and moves laterally inside hotel reservation networks. Password-protected archives are a favored evasion trick: the encrypted container blocks static inspection, so scanners see only ciphertext, and the payload decrypts only when the victim opens it with the shared password (MITRE T1027.002). The Archive Engine handles the challenge differently - it decrypts and extracts archive contents, recursively unpacks nested files, and passes every extracted item through multi-engine scanning and content inspection. The demo uses a benign RAR protected with a known password and containing only harmless test content.

Attack Technique

Password-protected archive

MITRE ATT&CK

T1027.002 ↗

Platforms

linuxwindows

File Types

.rar

MetaDefender Capabilities

Archive Engine

Incident Coverage

This attack technique maps to a real-world security incident — read the daily digest for details: Read the incident digest ↗

--- ---