typeentityconfidencelowcreated2026-08-08updated2026-08-08malware-familyloaderdefense-evasionsocial-engineering

Setup Factory Dropper

A cluster of malware samples that repurpose the legitimate Setup Factory installer-builder runtime as a payload delivery mechanism. The outer binary is the unmodified or lightly modified Setup Factory launcher; the threat actor embeds malicious files inside the installer data region (overlay) and distributes the package under social-engineering filenames.

Overview

Attribute Detail
Platform Windows PE32 x86
Toolchain MSVC 6.0 linker, Setup Factory 7.0 runtime (2004 vintage)
Sections .text, .rdata, .data, .rsrc
Signing Unsigned
Distribution Social-engineering filenames (e.g. language-pack installers, document lures)

Build / RE

  • Outer stub is the standard Setup Factory runtime (suf70_launch.exe). Identified by VersionInfo strings: "Setup Factory 7.0 Runtime", "Indigo Rose Corporation", internal name suf70_launch.^[exiftool.json:36-46]
  • Overlay begins after the .rsrc section (offset varies by build; observed at raw offset 0x11000). The overlay contains an encrypted data region followed by a password-protected ZIP archive.^[rabin2-info.txt:23]
  • No anti-analysis in the outer stub. No debugger checks, VM detection, or API hashing. The threat actor relies on the installer legitimacy and filename lure for evasion.

Deploy / TTPs

ATT&CK ID Technique Implementation
T1204.002 Malicious File Distributed with social-engineering filenames (e.g. 点击此处安装简体中文.exe).^[triage.json]
T1027.002 Obfuscated Files / Encrypted Password-protected ZIP archive in the overlay conceals inner payloads.
T1055 Process Injection PeLoader filename in extracted archive suggests reflective PE loading; unconfirmed without dynamic execution.

Capabilities

  • setup-factory-overlay-payload-staging
  • password-protected-zip-payload-concealment
  • social-engineering-filename-lure
  • chromium-embedded-framework-payload-bundling (libcef.dll observed)
  • peloader-reflective-loading-suspected

Related Entities

  • silverfox — OpenCTI co-labels this sample as silverfox/valleyrat, but no build or behavioural overlap exists. Treat as false-positive tagging.
  • social-engineering-filename-lure — General technique used by this family.

Notable Analyses

  • 4ed636b326ee6fb52d8a820642afcabdacd2ae8a4449130101022349c4d4ae8e — Setup Factory 7.0 runtime dropper with 3.7 MB encrypted overlay containing libcef.dll, mediabox.exe, and PeLoader. Static-only. ZIP password not recovered.