Threat actors are hiding an OpenSUpdater reflective loader inside a recompiled 7-Zip self-extracting archive (SFX) module.