logo

APT27__2021__SSTIC2021-Article-Taking_Advantage_of_PE_Metadata_or_How_To_Complete_your_Favorite_Threat_Actor_Sample_Collection-lunghi.pdf

ID: a67c090d-64b9-4567-9a4d-14e15e9b76c1

STIX ID: report--a67c090d-64b9-4567-9a4d-14e15e9b76c1

Threat Score

75/100

Uploaded: 2026-08-07

Published Date: 2026-02-13

Last Modified Date: 2026-02-13

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This paper documents an investigation into the SysUpdate malware family attributed to Iron Tiger (Emissary Panda), demonstrating how defenders can expand from a single sample to many related samples and IOCs by pivoting on PE metadata such as filenames, import hashes, the RICH header, stolen code-signing certificates, and fuzzy hashes; it includes concrete examples, Yara rules, and notes on delivery and in-memory execution techniques used in targeted cyberespionage campaigns.