
Scully Spider's 14-File Catalog Reveals a Decade of Mandatory Packing
A CTX Team analysis of 14 executables attributed to Scully Spider (TA547) finds that six malware families spanning nearly two decades share a single operational signature: every destructive payload is packed before release. The evasion stack combines UPX runtime packing, ConfuserEx .NET obfuscation, MPress, ASPack, and — in the most sophisticated sample — an embedded reflective DLL loader enabling in-memory injection without writing to disk.
Fourteen executable files. Six malware families spanning nearly two decades of Windows-targeting tradecraft. No shared infrastructure, no code-signing certificates, no passive DNS to pivot on — and yet a single, unmistakable operational signature runs through every destructive payload in the set: before anything reaches a victim machine, it gets packed.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read