logo

Static Unpacking for the Widespread NSIS-based Malicious Packer Family

ID: f15c4ae4-91d3-5c90-a9b1-66ddc6600576

STIX ID: report--f15c4ae4-91d3-5c90-a9b1-66ddc6600576

Feed Name: Check Point Research

Threat Score
70/100

Date Published: 2024-05-28

Date Updated: 2026-04-27

Author: alexeybu

...
...

This report analyzes a widespread NSIS-based crypter family called “NSIXloader” used to pack and protect diverse malicious payloads (loaders, stealers, RATs). It documents common NSIS package layouts, DLL/EXE/plugin variants, shellcode and payload decryption routines (including XOR, cyclic shifts, and a modified RC4), provides techniques and Python pseudocode for automated static unpacking, and lists multiple SHA256 IOCs tied to known malware families.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.