PDFly Variant Uses Custom PyInstaller Modification, Forcing Analysts to Reverse-Engineer Decryption
ID: 01dd2996-1c81-56dd-920a-eee7b4708696
STIX ID: report--01dd2996-1c81-56dd-920a-eee7b4708696
Feed Name: cybersecurityNews.com
A new PDFly malware variant alters the PyInstaller stub with a custom magic cookie and implements a multi-stage encryption pipeline (XOR with 13- and 7-byte keys, zlib decompression, and byte reversal) to hide Python bytecode in the PE overlay. Researchers traced the modifications in pyimod01_archive.pyc, extracted the XOR keys, developed a generic extractor that recognizes the custom cookie and decrypts variants, and linked PDFly (and a related sample PDFClick) to an ongoing campaign that uses these evasion techniques.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
