Windows Packer pkr_mtsi Powers Widespread Malvertising Campaigns with Multiple Malware
ID: 652afd24-2eef-5d0b-bc70-9d8c76f4bca5
STIX ID: report--652afd24-2eef-5d0b-bc70-9d8c76f4bca5
Feed Name: GBHackers
**Windows packer pkr_mtsi enabling malvertising-driven distribution:** Researchers observed a custom Windows packer, pkr_mtsi, used since April 2025 to wrap trojanized installers and deliver multiple malware families (including Oyster, Vidar, Vanguard Stealer, Supper) via fake download portals promoted through paid malvertising and SEO poisoning; the report details its stable staged architecture (pkr_mtsi layer → degraded UPX intermediary → final payload), distinctive unpacking behavior (memory allocation then dense small writes), obfuscation and anti‑analysis quirks (PE header/UPX stripping, hashed API resolution, debugger checks, anomalous NtProtectVirtualMemory calls), and defensive opportunities such as behavioral detections and YARA rules to catch variants.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
