Researchers reported a new PDFly malware variant that uses a custom-modified PyInstaller executable to break common unpacking workflows and force manual reverse engineering. The sample alters PyInstaller identifiers (including a non-standard “magic cookie”) and corrupts strings so tools like PyInstxtractor fail to recognize the archive structure; even after adapting extraction scripts to accept the custom cookie and bypass validation checks, the recovered Python components remained multi-layer encrypted, with decryption logic implemented in separate bootstrap files that handle runtime extraction.
Separately, an educational malware-analysis write-up detailed how to unpack SnappyBee (Deed RAT), a modular backdoor previously reported in China-linked espionage activity and associated in public reporting with Salt Typhoon / Earth Estries. The post describes SnappyBee’s custom packing routine used to obscure its payload and evade static analysis, and positions the unpacking methodology as a repeatable approach for triaging similarly packed malware (including post-compromise tooling used for persistence and follow-on deployment such as Cobalt Strike and the Demodex rootkit).

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
Darktrace released a technical analysis of SnappyBee (Deed RAT), describing its DLL side-loading execution chain, ARC4-based decryption, in-memory staging, and debugger-based unpacking workflow for recovering later-stage payloads.
After reverse-engineering the scheme, Samplepedia produced a more generic extractor capable of locating custom cookie structures and automatically recovering XOR keys from pyimod01_archive.pyc to decrypt future variants.
Samplepedia analysts determined the malware's decryption logic resided in separate bootstrap components and documented a multi-stage process involving XOR, zlib decompression, a second XOR, byte reversal, and unmarshaling into Python code objects.
Analysts found a related sample named PDFClick that used the same custom PyInstaller-based evasion approach, indicating active development and a wider malware evasion campaign.
Security researcher Luke Acha first publicly identified a PDFly malware variant using a modified PyInstaller executable designed to break standard extraction and analysis workflows.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.