logo

PDFly Variant Uses Custom PyInstaller Modification, Forcing Analysts to Reverse-Engineer Decryption

ID: 01dd2996-1c81-56dd-920a-eee7b4708696

STIX ID: report--01dd2996-1c81-56dd-920a-eee7b4708696

Feed Name: cybersecurityNews.com

Threat Score
65/100

Date Published: 2026-02-03

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

A new PDFly malware variant alters the PyInstaller stub with a custom magic cookie and implements a multi-stage encryption pipeline (XOR with 13- and 7-byte keys, zlib decompression, and byte reversal) to hide Python bytecode in the PE overlay. Researchers traced the modifications in pyimod01_archive.pyc, extracted the XOR keys, developed a generic extractor that recognizes the custom cookie and decrypts variants, and linked PDFly (and a related sample PDFClick) to an ongoing campaign that uses these evasion techniques.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.