logo

Versatile Malware Loader pkr_mtsi Delivers Diverse Payloads

ID: da4ab622-100f-5a69-b8ab-76ab735751aa

STIX ID: report--da4ab622-100f-5a69-b8ab-76ab735751aa

Feed Name: Infosecurity Magazine (News)

Threat Score
70/100

Date Published: 2026-01-07

Date Updated: 2026-04-22

...
...

ReversingLabs identified a Windows packer called pkr_mtsi (first observed April 24, 2025) used as a flexible loader in large-scale malvertising and SEO-poisoning campaigns that deliver trojanized installers for legitimate utilities; it has been used to deploy multiple stealer families and other payloads. The report details the packer’s staged architecture, evolving obfuscation and anti-analysis techniques (modified UPX stages, hashed API resolution, junk GDI calls, anti-debug checks), DLL execution paths (regsvr32.exe, COM persistence), and detection opportunities such as a broad YARA rule and a predictable NtProtectVirtualMemory error pattern to aid triage and detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.