logo

Unpacking the packer ‘pkr_mtsi’

ID: 6a09e24e-fd4d-59bc-af88-e38cedf272c3

STIX ID: report--6a09e24e-fd4d-59bc-af88-e38cedf272c3

Feed Name: ReversingLabs Blog

Threat Score
75/100

Date Published: 2026-01-06

Date Updated: 2026-04-29

Author: Robert Simmons

...
...

Technical analysis of the pkr_mtsi Windows packer observed since April 2025 being used in large-scale malvertising and SEO-poisoning campaigns to distribute trojanized installers. The report describes consistent early-stage behaviors (memory allocation followed by dense small immediate-value writes), obfuscated API/PEB-based resolution (including ZwAllocateVirtualMemory hashing), pervasive junk GDI calls, anti-debugging and other evasive techniques, a modified/stripped UPX intermediate stage, and a defective NtProtectVirtualMemory usage that yields a high-signal detection opportunity; it concludes with comprehensive YARA rules and detection guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.