The ZIP header is altered to claim that its contents are uncompressed .
For the malware to work, it typically requires a specialized "loader" to correctly interpret the malformed data, making it harder to trigger by accident. 💻 Technical Breakdown: How it Works PROTHOM(Frozen)zip
Security vendors (like Malwarebytes ) are actively updating their engines to ignore the header and perform "brute-force" decompression. The ZIP header is altered to claim that