A newly published archive-parsing weakness, CVE-2026-0866 (dubbed “Zombie ZIP”), enables attackers to craft malformed ZIP files that can evade many antivirus and EDR scanners by manipulating ZIP header metadata. The technique sets the ZIP entry’s compression method to STORED while the embedded content remains DEFLATED, causing security tools that trust the header to skip decompression and scanning, resulting in false negatives. The malformed archives also typically fail to open or extract with standard ZIP utilities, which may surface errors such as CRC or unsupported method failures.
Technical analysis shows the inconsistency can be detected by inspecting ZIP record metadata (e.g., STORED entries where compressed and uncompressed sizes differ) and by using tooling that bypasses standard ZIP libraries to parse raw records and forcibly decompress data. The SANS ISC write-up demonstrates analysis workflows and updates to zipdump.py (including a forcedecompress capability) to recover the hidden payload (illustrated with an embedded EICAR test file), while reporting indicates real-world abuse would likely pair the malformed archive with a custom loader that ignores the falsified header and directly extracts/decompresses the concealed content for execution.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
A later report said that six days after public disclosure, 60 of 63 antivirus products still failed to detect the Zombie ZIP technique, indicating that vendor protections had not materially improved after the initial disclosure.
Didier Stevens' zipdump.py version 0.0.35 added a new "forcedecompress" option to attempt decompression regardless of the declared ZIP compression method, enabling analysis of malformed Zombie ZIP archives.
SANS Internet Storm Center published technical analysis showing how Zombie ZIP archives declare files as STORED while actually containing DEFLATED data, and demonstrated recovery of a hidden EICAR test file from a malformed sample.
Early public reports on the disclosure said the technique bypassed detection in the vast majority of tested antivirus products, with one account citing 50 of 51 engines fooled and another saying only Kingsoft detected the sample on VirusTotal.
CERT/CC published Vulnerability Note VU#976247 for CVE-2026-0866, documenting the malformed ZIP parsing issue, confirming Cisco as affected, listing many other vendors as unknown, and recommending validation of archive content rather than trusting ZIP metadata.
Security researcher Chris Aziz of Bombadil Systems developed a malformed ZIP archive technique later dubbed "Zombie ZIP," which falsifies ZIP header compression metadata so embedded malicious content can evade antivirus and EDR scanning while remaining recoverable with a custom loader.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
7 references tracked. Mallory keeps watching after this page renders.
tomshardware.com
Open sourcescworld.com
Open sourcecsoonline.com
Open sourceisc.sans.edu
Open sourceisc.sans.edu
Open sourcecybersecuritynews.com
Open sourcecyberpress.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.