Researchers detailed how PyInstaller-packed Python executables on both Windows and Linux can be reverse engineered to recover embedded bytecode and reconstruct malware logic. Fortinet showed that Windows samples built with Python 3.8 can be unpacked with pyinstxtractor and decompiled with uncompyle6, while Linux ELF samples may require dumping the pydata section before extraction and using Decompyle++ for Python 3.9 bytecode. In one Linux sample recovered from VirusTotal, the unpacked contents included RansomWare.pyc, indicating a ransomware payload, though some functions required bytecode disassembly or dynamic analysis because decompilation was incomplete.
Separate analysis of a PyInstaller-packed sample distributed through a Discord community recovered a multi-stage Python stealer that used Base64, junk code, XOR, AES-CBC, and compressed payloads to hide its final logic. The recovered stages ultimately decrypted and executed a Python payload associated with Creal Stealer and sent data to the attacker-controlled domain mgststudio.shop. Supporting documentation from the pyinstxtractor project also outlined the Linux ELF extraction process used to recover embedded Python files from packaged binaries.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
A researcher analyzed a PyInstaller-packed Python malware sample obtained via a Discord community, recovered multiple staged payloads, and identified the final code posting data to the attacker-controlled domain mgststudio.shop. The write-up linked the sample to Creal Stealer and described layered obfuscation including Base64, XOR, AES-CBC, and compression.
Fortinet published research showing how to unpack PyInstaller-built executables on Windows and Linux, including analysis of a real Linux ELF malware sample from VirusTotal. The unpacked sample contained RansomWare.pyc, was assessed as ransomware, and Fortinet provided detections and IOCs.
A GitHub wiki page for pyinstxtractor documented a method for extracting Linux ELF binaries, providing background relevant to later PyInstaller malware analysis workflows.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
kienmanowar.wordpress.com
Open sourcefortinet.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.