Attackers have been delivering malware in compressed archives that unpack into abnormally large executables, using zero-filled padding and nested container formats to push files beyond common endpoint detection and sandbox scanning limits. Researchers described ZIP archives as small as 2 MB to 2.5 MB expanding into ISO images or PE files hundreds of megabytes to more than 2 GB in size, even though the functional malware payload was often only about 1 MB to 1.8 MB once the appended overlay was removed. The technique exploits the fact that some EDR products and analysis pipelines skip or time out on files above thresholds such as 1 GB or 2 GB.
Multiple campaigns used the approach to deliver commodity malware including BitRAT, LokiBot, and other .NET payloads. In one case, analysts extracted a BitRAT sample with configuration pointing to kot-pandora[.]duckdns[.]org:24993, version 1.38, TOR process name tor, and password d6723e7cd6735df68d1ce4c704c29a04; in another, a phishing lure named "Purchase Order pdf.zpaq" used the uncommon ZPAQ format to drop a 1 GB executable that fetched an obfuscated payload from MediaFire. Separate malspam also paired ZIP and ISO files with social-engineering tricks, including malformed sender headers that made Outlook display only a trusted-looking name, showing how archive inflation and phishing deception are being combined to reduce detection and increase user execution.

Get the infrastructure and lures behind it.
4 events from the most recent confirmed update back to the earliest known activity.
Gatewatcher analyzed a likely malicious PE file inflated to about 2.1 GB with zero-byte padding, allowing it to compress into a 2.5 MB ZIP while potentially exceeding common EDR file-size scanning thresholds. The write-up said the technique is not new but is resurfacing as attackers adapt to widespread EDR deployment.
A phishing attempt captured by a honeypot used a ZPAQ archive named "Purchase Order pdf.zpaq," an uncommon format that common Windows tools could not decompress. Extraction with zpaq revealed a 1 GB .NET executable that appeared to download an obfuscated payload from a MediaFire URL, consistent with oversized-file evasion tactics.
A malicious email-delivered 2 MB ZIP archive contained an ISO with a 400 MB PE file whose size was inflated by a 99% zero-filled overlay. After stripping the padding, the analyst identified the 1.8 MB .NET executable as BitRAT and extracted configuration including version 1.38 and C2 kot-pandora[.]duckdns[.]org:24993.
A phishing email captured by a spam trap delivered LokiBot via a ZIP archive containing an ISO and NSIS-built executable, while also abusing a non-RFC-compliant From header that made Outlook show only a trusted-looking sender name. The malware decoded and loaded LokiBot in memory, attempted persistence and data theft, and its C2 returned HTTP 404 responses at the time of analysis.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 13 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
4 references tracked. Mallory keeps watching after this page renders.
gatewatcher.com
Open sourceisc.sans.edu
Open sourceisc.sans.edu
Open sourceisc.sans.edu
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.