Join our Newsletter — 33% off our NHI Course
Home› FAQ› Threats, Abuse & Incident Response› What happens when a user clicks a payroll…
Threats, Abuse & Incident Response

What happens when a user clicks a payroll lure that leads from PDF to ZIP to MSI?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 28, 2026 Domain: Threats, Abuse & Incident Response

The click can move the victim from email to a hosted archive, then to a compressed installer that deploys remote administration software. Once installed, the tool can provide the attacker with interactive access and a foothold for follow-on activity. In practice, a single click can turn a social engineering lure into remote control over the endpoint.

How the lure chain changes from PDF to ZIP to MSI

The sequence matters because each hop changes the victim’s expectation and the attacker’s delivery options. A PDF can serve as the initial lure, a ZIP can hide the payload from casual inspection and some email filters, and an MSI can act as the installer that places software on the endpoint with the user’s help. The chain is less about the file types themselves than about progressively reducing friction until code is executed.

Once the archive and installer are opened, the attacker can move from simple delivery to execution. That is why these campaigns often look like a boring document download at first, then become a software installation event on the endpoint.

Why the MSI stage is the real turning point

An MSI is important because it is designed to install software, which gives the attacker a credible path to persistence and interactive access. In many cases the payload is not an obvious malware dropper at the first step, it is a remote administration tool or similar software that blends in with legitimate administration products. The user’s own action can supply the trust boundary crossing that makes the installation succeed.

That turning point is what makes the lure dangerous. The attacker no longer depends only on convincing someone to open a file, they now have a foothold that can be used for remote control, command execution, data discovery, or further payload delivery.

What practitioners should expect after initial execution

After installation, the immediate concern is not just compromise, but follow-on activity. An interactive remote access tool can let the operator explore the endpoint, harvest additional credentials, stage additional malware, and pivot into connected systems if the environment allows it. Even when the first payload is a commodity remote administration product, the post-install actions can quickly become broader intrusion activity.

That makes this pattern different from a one-off nuisance download. The chain is often a delivery mechanism for a living session, which means defenders need to think in terms of endpoint containment, command visibility, and downstream identity and access impact rather than only file quarantine.

Risk and Threat Considerations

This lure chain is risky because it turns a single click into execution, then into operator-controlled access. The threat is not limited to the payload itself, it is the combination of social engineering, archive concealment, and an installer that can create an immediate foothold on a workstation.

Failure mechanism: The initial lure gets the user to open a document, then follow a download path to a ZIP and launch an MSI that installs remote access software under the appearance of a normal installer.

Impact: The attacker can gain interactive control of the endpoint, use that access for persistence or lateral movement, and expand the incident beyond the original mailbox or workstation.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK addresses the attack and risk surface, while CIS Controls v8 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
MITRE ATT&CKT1204 — User ExecutionThe lure relies on the user opening and launching the payload chain.
T1059 — Command and Scripting InterpreterRemote administration tools enable attacker command execution after install.
T1105 — Ingress Tool TransferThe ZIP and MSI delivery path is a staged tool transfer to the endpoint.
Recommendation — Map the chain to user-execution tactics and hunt for the first malicious launch event. Correlate the installed tool with post-execution command activity and remote control. Track the download chain and block staged payload retrieval before execution.
CIS Controls v8CIS-10 — Malware DefensesThis is a malware delivery and execution pattern that needs endpoint prevention and detection.
Recommendation — Use malware defenses to detect the archive-to-installer chain and isolate compromised hosts.
NIST SP 800-53 Rev 5SI-3 — Malicious Code ProtectionThe payload is delivered and installed as malicious code on the endpoint.
Recommendation — Apply malicious code protection to detect and block the installer before it runs.

Practitioner Guidance

What to verify: Treat the file chain as a delivery-and-execution event, not a simple attachment issue. If telemetry shows PDF-to-ZIP-to-MSI behavior, confirm whether the MSI created a new service, launched an unexpected remote administration process, or reached out to external infrastructure immediately after install.

What to prioritise: Contain the endpoint first if execution is confirmed, then assess whether the payload touched credentials, browser sessions, or local admin rights. The practical question is whether the installer only ran, or whether it established durable access that survives a reboot or user logoff.

Common mistake: Teams often stop at email deletion or URL blocking after the lure is reported. That is insufficient when the payload has already been installed, because the real control problem is endpoint foothold removal and scope assessment, not just message cleanup.

Practitioner takeaway: The key decision is whether the MSI produced a controllable remote session, if it did, assume the incident has moved from phishing to endpoint compromise and respond accordingly.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 28, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org