These are the file types most likely to be hiding malware


For the first time in three years, Microsoft Office files are no longer the most common file type for malware distribution. That’s according to HP Wolf Security’s latest Threat Insights Report (opens in new tab) for Q3 2022.
Analyzing data from “millions of endpoints” running its cybersecurity solution, HP concluded that archive files (.ZIP and .RAR files, for example) surpassed Office files to become the most common way to distribute malware.
In fact, 44% of all malware delivered in Q3 2022 used this format, up 11% on Q2. Office files, on the other hand, accounted for 32% of all malware distributions.
Bypassing protections
HP also found that Archive files would usually be combined with an HTML smuggling technique, in which cybercriminals would embed malicious archive files into HTML files to avoid being detected by email security solutions.
“Archives are easy to encrypt, helping threat actors to conceal malware and evade web proxies, sandboxes, or email scanners,” said Alex Holland, Senior Malware Analyst for the HP Wolf Security threat research team.
“This makes attacks difficult to detect, especially when combined with HTML smuggling techniques.”
Holland used the recent QakBot and IceID campaigns as examples. In these campaigns, HTML files were used to direct victims to fake online document viewers, with victims being encouraged to open a .ZIP file and unlock it with a password. Doing so would infect their endpoints with malware.
“What was interesting with the QakBot and IceID campaigns was the effort put in to creating the fake pages – these campaigns were more convincing than what we’ve seen before, making it hard for people to know what files they can and can’t trust,” Holland added.
HP has also said that cybercriminals evolved their tactics to develop “complex campaigns” with a modular infection chain.
This allows them to switch up the type of malware delivered mid-campaign, depending on the situation. Crooks could deliver spyware, ransomware, or infostealers, all using the same infection tactics.
The best way to protect against these attacks, the researchers say, is to adopt a Zero Trust approach to security.
“By following the Zero Trust principle of fine-grained isolation, organizations can use micro-virtualization to make sure potentially malicious tasks – like clicking on links or opening malicious attachments – are executed in a disposable virtual machine separated from the underlying systems,” explains Dr Ian Pratt, Global Head of Security for Personal Systems at HP.
“This process is completely invisible to the user, and traps any malware hidden within, making sure attackers have no access to sensitive data and preventing them from gaining access and moving laterally.”
Audio player loading… For the first time in three years, Microsoft Office files are no longer the most common file type for malware distribution. That’s according to HP Wolf Security’s latest Threat Insights Report (opens in new tab) for Q3 2022. Analyzing data from “millions of endpoints” running its cybersecurity…
Recent Posts
- I have good news and bad news about Windows 11 24H2’s new update: it introduces nifty features and fixes… but also includes another ad
- Where to Stream 2025’s Best Picture Oscar Nominees
- The hidden costs of data subject access requests (DSARs) on privacy
- Amazon Alexa event live – latest news and rumors ahead of devices and service announcements
- Everything new on Disney+ in March 2025: Marvel’s Daredevil: Born Again, Moana 2, Sadie Sink’s O’Dessa movie, and more
Archives
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022
- December 2021
- November 2021
- October 2021
- September 2021
- August 2021
- July 2021
- June 2021
- May 2021
- April 2021
- March 2021
- February 2021
- January 2021
- December 2020
- November 2020
- October 2020
- September 2020
- August 2020
- July 2020
- June 2020
- May 2020
- April 2020
- March 2020
- February 2020
- January 2020
- December 2019
- November 2019
- September 2018
- October 2017
- December 2011
- August 2010