APT27__2021__SSTIC2021-Article-Taking_Advantage_of_PE_Metadata_or_How_To_Complete_your_Favorite_Threat_Actor_Sample_Collection-lunghi.pdf
ID: a67c090d-64b9-4567-9a4d-14e15e9b76c1
STIX ID: report--a67c090d-64b9-4567-9a4d-14e15e9b76c1
Threat Score
75/100
Uploaded: 2026-08-07
Published Date: 2026-02-13
Last Modified Date: 2026-02-13
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This paper documents an investigation into the SysUpdate malware family attributed to Iron Tiger (Emissary Panda), demonstrating how defenders can expand from a single sample to many related samples and IOCs by pivoting on PE metadata such as filenames, import hashes, the RICH header, stolen code-signing certificates, and fuzzy hashes; it includes concrete examples, Yara rules, and notes on delivery and in-memory execution techniques used in targeted cyberespionage campaigns.
