FILEMembers
FILE

Scully Spider's 14-File Catalog Reveals a Decade of Mandatory Packing

A CTX Team analysis of 14 executables attributed to Scully Spider (TA547) finds that six malware families spanning nearly two decades share a single operational signature: every destructive payload is packed before release. The evasion stack combines UPX runtime packing, ConfuserEx .NET obfuscation, MPress, ASPack, and — in the most sophisticated sample — an embedded reflective DLL loader enabling in-memory injection without writing to disk.

Jun 1, 2026, 07:20 (UTC+9)Last seenJun 1, 2026Severity98ByCTX TeamActorScully SpiderTA547IOC14MITRE8

Fourteen executable files. Six malware families spanning nearly two decades of Windows-targeting tradecraft. No shared infrastructure, no code-signing certificates, no passive DNS to pivot on — and yet a single, unmistakable operational signature runs through every destructive payload in the set: before anything reaches a victim machine, it gets packed.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence