Versatile Malware Loader pkr_mtsi Delivers Diverse Payloads
ID: da4ab622-100f-5a69-b8ab-76ab735751aa
STIX ID: report--da4ab622-100f-5a69-b8ab-76ab735751aa
Feed Name: Infosecurity Magazine (News)
ReversingLabs identified a Windows packer called pkr_mtsi (first observed April 24, 2025) used as a flexible loader in large-scale malvertising and SEO-poisoning campaigns that deliver trojanized installers for legitimate utilities; it has been used to deploy multiple stealer families and other payloads. The report details the packer’s staged architecture, evolving obfuscation and anti-analysis techniques (modified UPX stages, hashed API resolution, junk GDI calls, anti-debug checks), DLL execution paths (regsvr32.exe, COM persistence), and detection opportunities such as a broad YARA rule and a predictable NtProtectVirtualMemory error pattern to aid triage and detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
