Zero-Day Exploit in 7-Zip Fuels SmokeLoader Attacks on Ukraine

Red | Vulnerability Report
Download PDF

A critical zero-day flaw in the 7-Zip archiver, tracked as CVE-2025-0411, has been actively exploited since September 2024. This vulnerability allows attackers to bypass Windows’ Mark of the Web (MotW) security feature, enabling the seamless execution of malicious files. Russian cybercrime groups actively leveraged this flaw in spear-phishing campaigns, using sophisticated homoglyph attacks to spoof document extensions. This tactic deceived users ultimately facilitating the delivery of SmokeLoader malware in targeted attacks.

What’s new on HivePro

Get through updates and upcoming events, and more directly in your inbox