Malware, Threat Intelligence

Increased stealth integrated into flexible pkr_mtsi malware loader

Infosecurity Magazine reports that the illicit Windows packer pkr_mtsi, used to deploy the Vidar, Oyster, Vanguard Stealer, and Supper payloads through counterfeit installers of popular utilities, has been upgraded with hashed API resolution, more robust obfuscation, and enhanced anti-analysis mechanisms over the last eight months.

Aside from utilizing modified UPX-packed intermediate stages and obfuscated calls to ZwAllocateVirtualMemory, the evolved pkr_mtsi packer also employs junk calls to GDI API functions and anti-debugging checks to prevent analysis and terminate processes, respectively, an advisory from ReversingLabs noted. Additional findings showed that the versatile malware loader enables execution through regsvr32.exe and other Windows utilities, while using registry-based COM registration for persistence.

"For DFIR practitioners, understanding the packer's staged architecture, modified UPX intermediary, and alternate execution paths, especially DLL-based execution via regsvr32.exe, enables faster triage, more reliable unpacking, and clearer separation of packer behavior from payload functionality," said the ReversingLabs team.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds