typeentityconfidencelowcreated2026-08-27updated2026-08-27malware-familyloaderpeinstallerevasionsigningmasquerading

xryus-inno-dropper

Overview

Inno Setup 6.7.0 installer family masquerading as EasySuiteer Setup by SuperPlus MegaPacker. Authenticode-signed with a Microsoft ID Verified code-signing chain (leaf CN Xryus Technologies LLC, Delaware, 72-hour validity). The outer binary is a legitimate installer framework; threat logic lives in a 55.7 MB encrypted LZMA overlay that is invisible to static tools without the embedded decryption key. First confirmed sample in this knowledge base.

Confidence: low — single observed sample. Structurally aligned with the broader Inno Setup abuse cluster (poabu-inno-dropper, netsupport-inno-dropper, tofsee) but carrying a distinct certificate chain, masquerade identity, and no observed payload extraction.

Build Stack

  • Toolchain: Inno Setup 6.7.0 (Delphi / Object Pascal compiler) ^[sample 45002243/strings.txt:7552]
  • Arch: PE32 (x86), Windows GUI subsystem ^[sample 45002243/file.txt]
  • Import Table: Standard IAT intact; delay-imports for kernel32.dll and user32.dll ^[sample 45002243/pefile.txt:DelayImport]
  • Overlay: 55.7 MB encrypted LZMA-compressed Inno Setup archive at offset 0xDA400 ^[sample 45002243/binwalk.txt]
  • Signing: Authenticode-signed (signed=true); Microsoft ID Verified chain with leaf CN Xryus Technologies LLC ^[sample 45002243/certificate-chain.txt]
  • Masquerade: Fabricated version info claiming EasySuiteer Setup by SuperPlus MegaPacker, ProductVersion 3.9.9 ^[sample 45002243/exiftool.json]

Capabilities

  • inno-setup-legitimate-installer-abuse
  • lzma-encrypted-overlay-archive
  • microsoft-id-verified-code-signing
  • version-info-masquerade
  • delay-import-anti-vm
  • easy-suite-social-engineering

Deploy / TTPs

Technique ID Evidence
Masquerading T1036.002 EasySuiteer Setup by SuperPlus MegaPacker ^[sample 45002243/exiftool.json]
Software Packing T1027.002 Encrypted LZMA-compressed Inno Setup archive (55.7 MB) ^[sample 45002243/binwalk.txt]
Code Signing T1553.002 Valid Authenticode with Microsoft ID Verified chain ^[sample 45002243/certificate-chain.txt]
Ingress Tool Transfer T1105 Drops unknown payload via Inno Setup NumFileEntries/NumRunEntries ^[sample 45002243/strings.txt:7151-7158]
Virtualization/Sandbox Evasion T1497.001 Delay-imported GetLogicalProcessorInformation for CPU-feature anti-VM ^[sample 45002243/pefile.txt:630]

Variants / Aliases

  • xryus-inno-dropper — this wiki label
  • EasySuiteer Setup — observed masquerade product name
  • SuperPlus MegaPacker — observed masquerade company name
  • Xryus Technologies LLC — certificate subject CN
  • Inner payload family unconfirmed (encrypted overlay unextracted)

Notable Analyses

  • /intel/analyses/450022431a5d5d5589895b878420747c860a85928d560f48355acbc8825ba744.html — 45002243, static-only, no CAPE detonation

Related

  • poabu-inno-dropper — structurally similar Inno Setup 6.7.0 installer family (Sectigo-signed, Tim Kosse cert, contact-service masquerade)
  • netsupport-inno-dropper — structurally similar Inno Setup 6.7.0 installer family (unsigned, Intel driver masquerade)
  • tofsee — structurally similar Inno Setup 6.7.0 installer family (unsigned, Blacker LLC masquerade, spam-botnet payload)
  • inno-setup-legitimate-installer-abuse — concept page for Inno Setup abuse in malware distribution
  • version-info-masquerade — generic masquerade technique
  • stolen-certificate-signing — concept page for certificate abuse (note: this cert may be attacker-provisioned rather than stolen; Microsoft ID Verified has low identity-assurance barriers)