Scworld Enhanced pkr_mtsi Malware Loader Distributes Multiple Payloads
Article Content
Browse articles
The pkr_mtsi malware loader has been upgraded to incorporate advanced stealth techniques, including hashed API resolution and improved obfuscation. Initially observed in April 2025, it is utilized for deploying various payloads through counterfeit software installers, impacting users through malvertising and SEO-poisoning campaigns.
Ask AI about this cluster
Answers cite the sources they use
Updated 183d ago How this analysis works
More articles in this cluster (2)
Following this threat?
Track Oyster in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
C2Looper Backdoor Exploits GitHub for Command-and-Control Operations In July 2026, Zscaler ThreatLabz identified C2Looper, a Rust-based backdoor likely linked to ransomware actors. The malware employs a multi-stage ClickFix infection chain and utilizes GitHub repositories for command-and-control, marking a significant evolution in its delivery method. C2Looper is capable of executing…
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…