Back Scworld Increased stealth integrated into flexible pkr_mtsi malware loader
Infosecurity Magazine reports that the illicit Windows packer pkr_mtsi, used to deploy the Vidar , Oyster, Vanguard Stealer, and Supper payloads through counterfeit installers of popular utilities, has been upgraded with hashed API resolution, more robust obfuscation, and enhanced anti-analysis mechanisms over the last eight months.
Aside from utilizing modified UPX-packed intermediate stages and obfuscated calls to ZwAllocateVirtualMemory, the evolved pkr_mtsi packer also employs junk calls to GDI API functions and anti-debugging checks to prevent analysis and terminate processes, respectively, an advisory from ReversingLabs noted. Additional findings showed that the versatile malware loader enables execution through regsvr32.exe and other Windows utilities, while using registry-based COM registration for persistence.
"For DFIR practitioners, understanding the packer's staged architecture, modified UPX intermediary, and alternate execution paths, especially DLL-based execution via regsvr32.exe, enables faster triage, more reliable unpacking, and clearer separation of packer behavior from payload functionality," said the ReversingLabs team.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
