typeentityconfidencelowcreated2026-08-08updated2026-08-08malware-familyloaderdefense-evasionsocial-engineering
Setup Factory Dropper
A cluster of malware samples that repurpose the legitimate Setup Factory installer-builder runtime as a payload delivery mechanism. The outer binary is the unmodified or lightly modified Setup Factory launcher; the threat actor embeds malicious files inside the installer data region (overlay) and distributes the package under social-engineering filenames.
Overview
| Attribute |
Detail |
| Platform |
Windows PE32 x86 |
| Toolchain |
MSVC 6.0 linker, Setup Factory 7.0 runtime (2004 vintage) |
| Sections |
.text, .rdata, .data, .rsrc |
| Signing |
Unsigned |
| Distribution |
Social-engineering filenames (e.g. language-pack installers, document lures) |
Build / RE
- Outer stub is the standard Setup Factory runtime (
suf70_launch.exe). Identified by VersionInfo strings: "Setup Factory 7.0 Runtime", "Indigo Rose Corporation", internal name suf70_launch.^[exiftool.json:36-46]
- Overlay begins after the
.rsrc section (offset varies by build; observed at raw offset 0x11000). The overlay contains an encrypted data region followed by a password-protected ZIP archive.^[rabin2-info.txt:23]
- No anti-analysis in the outer stub. No debugger checks, VM detection, or API hashing. The threat actor relies on the installer legitimacy and filename lure for evasion.
Deploy / TTPs
| ATT&CK ID |
Technique |
Implementation |
| T1204.002 |
Malicious File |
Distributed with social-engineering filenames (e.g. 点击此处安装简体中文.exe).^[triage.json] |
| T1027.002 |
Obfuscated Files / Encrypted |
Password-protected ZIP archive in the overlay conceals inner payloads. |
| T1055 |
Process Injection |
PeLoader filename in extracted archive suggests reflective PE loading; unconfirmed without dynamic execution. |
Capabilities
- setup-factory-overlay-payload-staging
- password-protected-zip-payload-concealment
- social-engineering-filename-lure
- chromium-embedded-framework-payload-bundling (libcef.dll observed)
- peloader-reflective-loading-suspected
Related Entities
- silverfox — OpenCTI co-labels this sample as
silverfox/valleyrat, but no build or behavioural overlap exists. Treat as false-positive tagging.
- social-engineering-filename-lure — General technique used by this family.
Notable Analyses
4ed636b326ee6fb52d8a820642afcabdacd2ae8a4449130101022349c4d4ae8e — Setup Factory 7.0 runtime dropper with 3.7 MB encrypted overlay containing libcef.dll, mediabox.exe, and PeLoader. Static-only. ZIP password not recovered.