Windows Packer pkr_mtsi Powers Widespread Malvertising Campaigns Delivering Multiple Malware Families
ID: 669e8c04-badf-556e-964a-141ef49b41a4
STIX ID: report--669e8c04-badf-556e-964a-141ef49b41a4
Feed Name: cybersecurityNews.com
This report describes pkr_mtsi, a sophisticated Windows packer actively used in malvertising campaigns to deliver trojanized installers (targeting PuTTY, Rufus, Microsoft Teams) and multiple malware families (Oyster, Vidar, Vanguard Stealer, Supper); it details evolving obfuscation and anti-analysis techniques (obfuscated ZwAllocateVirtualMemory calls, chunked payload reconstruction, hashed API resolution, junk GDI calls, modified UPX stages) and notes inconsistent detection by antivirus products.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
