Back Recordedfuture Malware Crypting Services and the Threat Actors Who Sell Them
Crypting services and products modify malicious payloads to help threat actors bypass detection, complicate analysis, and preserve malware usability after exposure. Although basic crypting consists of encrypting or obfuscating a customer-supplied payload, mature providers increasingly operate as broader malware-enablement services. Their offerings often combine payload wrapping, in-memory execution, anti-analysis checks, process injection, persistence options, delivery packaging, and post-detection “cleaning” or re-crypting services.
Insikt Group analyzed 24 threat actors advertising crypting services and products within the past year and identified a market that is competitive, reputation-driven, and heavily focused on Windows payloads. Providers advertise through underground forums, restricted communities, chat platforms, clearnet sites, and social media accounts. They compete through tiered pricing, antivirus (AV) detection scores of crypted samples, discounts, malware-developer partnerships, private or shared stubs, and promised turnaround times for re-crypting detected payloads.
Advertised crypter capabilities vary by provider, but the underlying objectives are consistent: reduce detection, delay or prevent analysis, and support stealthier payload execution. Because crypted payloads are designed to defeat both static and dynamic analysis, defenders should prioritize behavioral detection over static indicators. See the Outlook and Mitigations section for details.
“Crypting” is what threat researchers generally refer to as a service or product wherein a file, almost exclusively a malicious executable of some kind, is encrypted to bypass malware detection technologies. The result of a crypting service is a malicious payload that modifies the supplied executable in ways that deter defenders and endpoint security solutions (namely, AV and EDR products) from detecting and analyzing it.
While the core functionality of a crypting service or product is to encrypt a payload, services vary in the capabilities they provide. These capabilities can range from the encryption algorithms used, which are often proprietary, to behavioral adjustments for how the resultant payload will execute in a victim environment. For instance, many crypting services include execution guardrails or methods for indicator suppression, such as ensuring execution fails in virtual environments or performing environmental scanning before execution to determine whether the payload is running in an analysis or sandbox environment.
The crypter landscape comprises a community of criminal threat actors that often operate on restricted or closed networks, including the dark web and underground forums, to market and sell their crypting services. Threat actors may also opt to market their services on clearnet websites they own and operate. In some instances, threat actors may be accessible only via messaging platforms, such as Telegram or TOX, which likely mask their exposure and reduce the likelihood of sensitive data leaking through forum chats. Finally, some threat actors have created social media accounts where they post updates on their services, partnerships, pricing, and links through which interested buyers can inquire purchases.
Additionally, partnerships between malware developers and crypting service providers are not uncommon. For instance, a well-established crypting service provider on underground forums, “GoldenCrypt”, is reportedly affiliated ( 1 , 2 , 3 ) with multiple malware families, including FvncBot, Albiriox, and Mirax. The level of affiliation between a crypting service provider and a malware developer can range widely, from providers with loose reputational ties to developers who are mainly affiliated with one hacking group and will opportunistically provide services to third parties. However, these partnerships are often a marketing strategy that crypting service providers use to secure kickbacks and boost positive reputational sentiment.
All of these services come at widely varying costs, typically based on core factors. For instance, crypting service fees are often tied to the volume and types of files to be encrypted, as well as the duration of service, with almost all crypting service providers offering tiered payment options along these lines. The actual prices of these tiers are pegged to additional factors related to the provider and their product, including the reputation of the threat actor, the capabilities of their encryption service, the promise that a crypted payload is fully undetectable (FUD), and additional features provided to the buyer. Threat actors will support the assertion that their payloads are FUD by using multi-AV platforms, the most common of which is KleenScan, a service that allows threat actors to scan samples without storing and potentially exposing the samples to researchers. As with other legitimate services, service providers also advertise discounts and similar deals to remain competitive with their peers.
Many threat actors have been observed in the wild using crypting services due to their stealth capabilities. All malware types can be crypted, and the key factors determining whether a threat actor can use a crypting service are the targeted device’s operating system and the payload’s programming language. For instance, the most common crypting services are geared toward Windows .exe and .dll payloads. Still, considerations such as whether a payload is coded in .NET, C, or C++ can provide additional capabilities for crypted payloads or, in other instances, prevent certain payloads from being crypted.
While the use of crypting services is common among threat actors, it is by no means ubiquitous. Due to sometimes prohibitive pricing strategies and an environment that often relies on reputational checks before purchase, crypting services are often used only by well-established criminal threat actors or larger threat actor groups that have their own specialist or custom tooling for crypting payloads. Furthermore, as discussed previously in this report, not all crypting services support all types of payloads. While this does not expressly ensure that a payload cannot be crypted, threat actors seeking to crypt more unique types of executables may find their options limited or even nonexistent.
Nevertheless, crypting services are commonly marketed by threat actors and are commonly implemented by professional threat actor groups. Multiple open-source reports on high-impact cyberattack campaigns have supported this. For instance, in July 2025, eSentire reported an association between PureRAT, a remote access trojan (RAT) first advertised in January 2023, and GhostCrypt, a crypting service sold by an underground forum member of the same moniker, in an attack that impacted a public US accounting firm in May 2025.
Insikt Group investigated 24 crypting service or product providers active within the past year and identified the various capabilities advertised by each. This information helped determine the capabilities most commonly displayed by crypting services, products, and the payloads they create, and provided insight into the capabilities most desirable to customers buying these services and products. A heat map of the techniques advertised by these threat actors is shown in Figure 1 , below. (The list of MITRE ATT&CK techniques shown in Figure 1 can also be found in Appendix B .)
Support for multiple payload formats and delivery mechanisms is one of the most commonly advertised capabilities beyond basic payload obfuscation. Providers advertise public, private, and shared stubs (unique wrappers applied to threat actor-supplied payloads generated by the crypting service or product); AES-256 payload encryption; runtime in-memory decryption; GZIP compression; junk code injection; string encryption; and unique polymorphic code per build. These capabilities are intended to make each crypted payload more difficult to identify through static signatures and to slow reverse engineering. Some services also offer repeated “cleaning” or updates to their encryption routines after detection, reflecting an operational model in which the provider continuously modifies the stub or payload wrapper to evade detection.
The most commonly targeted products for evasion techniques are Microsoft security controls, especially Windows Defender and SmartScreen. Other named targets include Kaspersky, ESET, Bitdefender, Norton, Avast, AVG, Malwarebytes, Trend Micro, CrowdStrike, SentinelOne, Carbon Black, and Microsoft Defender. These claims should be treated as provider-advertised capabilities unless corroborated through sample analysis, detection telemetry, or third-party reporting.
Many threat actors operate within the crypting service landscape, and while the main services they sell all achieve the same goal, the threat actors, their methods, and the results of their services are unique. This section discusses three notable threat actors, including their histories, the services they advertise, and technical details the products they produce.
To compare the differences between these threat actors and their respective services, Insikt Group analyzed 24 threat actors that actively sold crypting services within the past year, each residing in a separate “tier” of service provider based on the following stipulations:
Notably, these tiers do not address the veracity of the technical capabilities of these threat actors as displayed in their crypting services. In this landscape, if subpar service is provided, this discovery is often made early and, as a result, threat actors who provide it do not last long in the space. Therefore, all the threat actors discussed in this section (two Tier 1 and one Tier 2 threat actor), as well as the remaining 21 listed in Appendix A , are believed capable of providing technically sound crypting services and products.
mrlapis is a well-established vendor active across several darkweb and special-access forums. While mrlapis has been active since at least 2011, Insikt Group assesses that they are most notably associated with the development and sale of a crypting service referred to as “VIP Crypt”. On several forums, this threat actor has dedicated long-standing threads advertising their VIP Crypt service. Within these threads, the following points of are provided by mrlapis: Telegram (@mrlapis_real), Tox (2912CA4F42B6B37C749D759C43340959D5B9DE74E0242B83A3C5CF27FDADAA1DF83038A66255), and Jabber (mrlapis[@]exploit[.]im). Additionally, based on proprietary methods and sources used by Insikt Group, the following IP address was found to be associated with mrlapis: 46[.]183[.]217[.]105. This IP address is associated with the privacy-focused VPN service Air VPN and has an exit node in Latvia.
At the time of analysis, mrlapis advertised VIP Crypt on a subscription basis for $500 per week, with auto-renewal until canceled. For a first-time purchase, users are instructed to upload the file to be crypted to the temporary file upload service Temp[.]sh. Once the file is uploaded and verified by mrlapis, payment is requested. Upon receipt, the file will be delivered back to the user via Temp[.]sh. After this first-time purchase, users gain access to a secure file transfer protocol (FTPS), at which point the VIP Crypt team will crypt the files per the buyer's specifications. According to mrlapis, the file is re-encrypted every ten minutes. Based on proprietary methods and sources used by Insikt Group, mrlapis uses the following address as an FTPS server: 91[.]92[.]242[.]14[:]9090. When crypting is complete, the buyer is contacted, and the newly crypted files are sent to the buyer via the FTPS server, demonstrating the threat actor’s effort to ensure files are sent securely over an encrypted channel. Insikt Group has also previously observed mrlapis disseminating crypted content via FTPS from 5[.]61[.]36[.]246[:]9090. These addresses are likely two of many additional endpoints from which mrlapis and the VIP Crypt team deliver crypted payloads.
In the dark web and special-access forums services industry, seller longevity is rare and is linked to reputation on these platforms. In addition to the mrlapis’s longevity, the majority of feedback on underground forums is positive, with multiple community members endorsing mrlapis and VIP Crypt. While there is evidence that mrlapis previously had to engage in arbitration — a conflict resolution method that underground forum members will undergo when dissatisfied with a purchase (usually related to false advertising or fraud) within underground forum communities — these events are sparse and appear to have ended favorably for mrlapis, maintaining the theat actor’s reputation.
Just as mrlapis has been active since January 2011, Insikt Group assesses that VIP Crypt has been similarly active since this time based on mrlapis’s discussions on underground forums pertaining to the service. Over the years, the crypting service has experienced numerous updates and refinements, including multiple updates to operate effectively across every version of Microsoft Windows and to effectively bypass Windows-native AV solutions. Due to the comparatively large lookback period associated with VIP Crypt operations, Insikt Group gated the analysis of the service to its most recent significant update, version 3.0.
In June 2023, mrlapis posted the VIPCrypt 3.0 announcement on the underground forum Exploit, advertising a rewritten native crypting service designed to bypass AV products in real-world conditions. The operators claimed VIPCrypt 3.0 preserved advantages while improving detection avoidance, citing test results in which a Remcos RAT sample dropped from 18 of 25 detections on avcheck[.]net and 11 of 21 detections on scanner[.]to before crypting to 0 of 25 detections on avcheck[.]net and 1 of 21 detections on scanner[.]to after crypting. mrlapis also advertised that VIPCrypt 3.0 bypassed Windows Defender and Chrome Alert; did not use .NET or a dropper; supported payload generation for Windows XP, Windows 7, and later Windows versions; and could provide encrypted files through FTPS with automatic crypting every ten minutes and optional upload to customer-controlled servers.
Since June 2023, mrlapis has continued to advertise VIP Crypt updates focused on Windows Defender evasion, runtime bypasses, automated recryption, and stealthier payload execution. Across 2023 and 2024, mrlapis advertised local Windows Defender detection cleaning for submitted samples that could be retrieved from cloud infrastructure, during Chrome or Edge downloads, and from virtual private servers (VPS) in customer-selected countries. mrlapis also advertised additional updates, including runtime bypasses for AVG, Avast, Emsisoft, and Ikarus; a universal runtime bypass; process hollowing; indirect syscall-based EDR bypass; and support for crypting x64 Windows executables. In terms of user experience and quality-of-life updates, they also continued to advertise FTPS-based auto-crypting, customer-hosted uploads, crypted sample detection monitoring, custom modifications, “pumping,” and ZIP or RAR auto-archiving and unarchiving. Notably, during this time, mrlapis stated that they were unable to crypt APK files, a technical barrier for the developer that likely persists, as no evidence to the contrary has been posted to date.
Throughout 2025 and 2026, mrlapis continued advertising Windows Defender and .NET-focused improvements, including a .NET Windows Defender bypass, a Windows Defender Antimalware Scan Interface bypass for .NET assemblies, and dynamic-key recryption that changes file contents every ten minutes. More recent information from mrlapis alleges that their crypted outputs are still FUD, advertising FUD statuses for avcheck and Windows Defender Cloud, without requiring extended validation (EV) code-signing certificates.
Analysis of a recent VIP Crypt sample indicates that the service employs a multi-stage, Delphi-based loader designed to conceal and execute embedded payloads via an in-memory loading process.
The sample combines resource-based storage, segmented data structures containing non-functional padding, staged decoding, in-memory execution, and manual Portable Executable (PE) mapping to
conceal the embedded payload and complicate payload recovery. These techniques increase the difficulty of static analysis and reduce reliance on normal file-backed loading mechanisms that security tools commonly monitor. Execution is ultimately transferred from the decoded loader stage to a manually mapped payload, further obscuring the relationship between the initial executable and the final payload.
The sample is implemented as a Delphi application. During form initialization, the loader retrieves a protected loader stage stored within application resources. The resource data is organized into segmented blocks interspersed with non-functional padding, requiring reconstruction before decoding can occur. After reconstruction and decoding, the recovered loader stage executes in memory and serves as a second-stage loader that carries an embedded PE.
The second-stage loader prepares the embedded PE for execution without relying on the standard Windows image-loading process. Instead, it manually maps the PE into memory by allocating memory for the image, copying headers and sections, resolving imports, applying relocations, and setting memory protections before transferring execution to the payload entry point. As a result, the embedded PE is loaded and executed entirely through memory-resident loader code rather than through a normal file-backed loading sequence.
o1oo1 is a seller active on multiple dark web forums. The threat actor has been observed selling the malware encryption tool ASMCrypt and TOP RAT (aka SnappyClient), a commodity RAT first offered in September 2025. o1oo1 has a reputational score of 118, comprising 120 endorsements and two negative ratings, and has ten confirmed transactions.
While o1oo1 maintains a broadly positive forum reputation, the threat actor has also faced disputes related to service fulfillment and customer support. In one dispute, the threat actor “living” stated they paid $6,119 for a one-month subscription to RAT and crypter services and alleged that o1oo1 took three weeks to set up access to these services. o1oo1 disputed the complaint and accused the customer of attempting to manipulate the refund process; the customer ultimately received a 50% refund after removing allegedly false posts from the sales thread. o1oo1 also received allegations of ticket forgery and of removing prices from submitted tickets.
o1oo1 advertises their crypting service, ASMCrypt, for $3,000 per month. Customers who rent TOP RAT for $5,000 per month can rent ASMCrypt for $2,000 per month. o1oo1 advertises ASMCrypt as having customizable anti-virtual machine (anti-VM) functionality that can be configured based on minimum RAM and CPU requirements, banned hypervisors, system names, MAC addresses, and GPU names.
As discussed in the section, ASMCrypt serves as a builder for HijackLoader (also known as IDAT Loader) packages, which is how it obfuscates payloads. Public reporting indicates that HijackLoader supports capabilities such as API unhooking, direct and indirect syscall execution, stack spoofing, anti-debugging and anti-virtualization checks, security product detection that modifies execution behavior, and multiple configurable process injection techniques. By implementing the HijackLoader builder, ASMCrypt can provide its payloads with defense evasion and anti-analysis capabilities.
Analysis of samples crypted with ASMCrypt indicates that the crypter functions as a builder, generating HijackLoader packages. The observed execution chain combines several techniques commonly associated with defense evasion and staged payload delivery, including abuse of legitimate signed applications, DLL sideloading, externally stored encrypted configuration, working directory relocation, staged process creation, and process injection.
The analyzed packages implement a multi-stage loader architecture in which execution is distributed across multiple files, including a legitimate signed host application, a side-loaded DLL, and externally stored encrypted configuration data. This architecture combines signed application abuse, DLL side-loading, and modular configuration data to initiate execution.
Execution begins when the legitimately signed application is launched from the package directory and loads an attacker-controlled DLL through DLL side-loading. Static analysis showed that the side-loaded DLL reads encrypted external package data containing the HijackLoader configuration. The recovered configuration and module structure are consistent with the modular architecture of HijackLoader described in public reporting.
Dynamic analysis showed that the loader packages the components into a working directory under ProgramData , relaunches the signed application from that location, and continues execution from the staged package environment. Subsequent execution progresses through the HijackLoader execution chain before transitioning into later-stage payload execution. Sandbox telemetry observed staged process creation followed by memory injection activity, including remote memory writes and thread-context manipulation, consistent with HijackLoader’s established payload delivery methodology.
ImComplexed is a crypter vendor active on multiple criminal forums, with activity dating as far back as July 2020. The threat actor’s forum presence appears more established than that of new crypter vendors, and publicly available reputation data indicate a positive score of 40 as a seller.
The threat actor has faced disputes related to service fulfillment and customer support. In one forum thread, the buyer requested a refund through the forum's escrow arbitration process, stating that they paid $6,000 for a crypter advertised as 100% FUD and $2,500 for a one-year EV certificate, which was supposed to include full certificate files so they could sign their executables independently. According to the post, after payment, the seller failed to deliver the promised EV certificate files and instead provided an EV certificate that the buyer claims was unusable due to inconsistencies. The complainant also alleges that, rather than delivering the agreed-upon files, the seller insisted on using AnyDesk to access the buyer's VPS, which was not part of the original agreement.
ImComplexed advertises their malware crypter service with limited-time availability and multiple pricing tiers. ImComplexed offers a one-time crypter for $1,000 and several monthly subscription plans, including a $2,500 per month shared plan that allows one shared stub among up to five users with a claimed 24 to 48-hour "cleaning time,” and a $6,000 per month private plan that provides a dedicated stub with a claimed 24-hour “cleaning time.” (“Cleaning time” likely refers to the turnaround time to re-crypt an executable if a customer were to report a detection, and it likely serves as an agreement to prioritize requests for higher-tier customers.) ImComplexed also advertises premium packages priced at $12,000 and $20,000, which include additional features such as multiple simultaneous stubs, a pump feature, customized crypter configuration assistance, faster cleaning times, and, for the highest tier, a claimed User Account Control (UAC) exploit and near-instant cleaning. ImComplexed further notes that pricing for 32-bit and 64-bit crypters is separate, offers a discounted second architecture when purchasing one version, and advertises DLL crypting as an optional paid add-on. Overall, ImComplexed markets a range of crypter services and subscription packages intended to help software evade security detection, with varied pricing based on exclusivity, features, and turnaround time.
executable with an EV certificate. The threat actor has also advertised Netwire RAT, claiming to provide video proof of Windows Defender bypass.
Analysis of recent ImComplexed samples indicates that the crypter employs a multi-stage loader designed to disguise malicious activity behind a benign-looking Windows application while reconstructing and staging the protected payload in memory.
The analyzed samples present a Hyper-V Manager facade through application metadata, resources, strings, mutex names, and graphical user interface (GUI) initialization routines. During execution, the samples follow a conventional Windows GUI startup path, registering window classes and preparing user interface elements associated with Hyper-V Manager. Before the primary application window is created, however, execution is transferred into a large protected code section that contains the crypter’s loader.
Within the protected section, the loader performs multiple unpacking and reconstruction steps. The protected code uses chunked, obfuscated control flow and PE-aware module and export walking to bootstrap API resolution before preparing the stage. Encrypted data is decoded in memory before being decompressed into an executable memory region. Rather than producing a standalone PE file at this stage, the decompressed output serves as an executable intermediate stage that continues payload preparation and execution.
The intermediate loader launches a hidden, suspended instance of CMD.exe and stages loader and payload data buffers within the child process. The loader modifies the child thread’s startup context so that execution enters an injected handoff region, which transfers control to child-side loader code. That child-side code decodes and decompresses additional payload bytes before transferring control to the reconstructed payload.
The crypter distributes payload recovery across multiple protected stages rather than exposing a directly recoverable executable. Application masquerading, protected control flow, PE-aware module and export walking, encrypted payload storage, staged decompression, hidden suspended-process creation, thread-context manipulation, and child-side payload decoding all increase analysis complexity and reduce the value of static inspection of the original executable alone.
Crypting services are intended to defeat static and dynamic detection by obscuring payload structure, staging execution, and adding defense-evasion capabilities. The services analyzed in this report show that modern crypters increasingly operate as loader frameworks that combine payload encryption, anti-analysis checks, DLL sideloading, in-memory execution, process injection, manual PE mapping, and automated recryption. As a result, defenders should not rely on hashes, static signatures, or AV detections alone to identify crypted malware.
Defenders should prioritize behavior-based detection and response playbooks that focus on how crypted payloads execute rather than on how individual crypted files appear. Although crypting services and products differ in implementation, they a common objective: separating the initial executable from the final payload while suppressing security teams’ visibility during execution.
Recorded Future customers can hunt for and mitigate the threats associated with crypted malware by:
Detection engineering and threat hunting should prioritize the following behaviors:
Defenders also should pair behavior-based detections with hardening and response measures, including:
Detection logic should be built around durable loader behavior rather than crypter-specific artifacts. Crypted files can change quickly through recryption, but the behaviors required for payload staging, execution, persistence, and defense evasion are harder to eliminate. The strongest defensive opportunities are therefore not the crypted files themselves, but the execution patterns they must produce to deliver the final payload.
Table 1: Commonly targeted AV products and their associated process names. Each vendor and product is linked to its documentation, which may include additional executables that defenders should consider for monitoring.
As previously discussed in this report, Insikt Group investigated 24 threat actors in the crypting space. Below is a table of the notable threat actors that Insikt Group investigated (analysis cutoff: May 2026), in addition to those discussed in the section Prominent Crypting Service Threat Actors found earlier in this report.
Pricing: Currently selling crypts for $45 per crypt
Encrypting and packing EXE/.NET files to make each output look unique and harder to detect
Evasion capabilities, including low AV detection rates, “AV check” scans, runtime updates, and developer alerts when detections occur
Add-ons such as autostart persistence, anti-VM checks, process restart on kill, fake errors, IP logging, self-deletion, and UAC-spam admin prompts
File customization, including changing icons, copying version metadata, bundling multiple executables, and adding approximately ~800 to 900 KB overhead
While leaked chat information associated with the threat actor group Conti (of which Bentley was a member and provided crypting services) has surfaced, the chats did not directly mention specific technical capabilities the threat actor used when performing crypting actions.
Bentley has also not discussed specific crypting methodology in open sources.
Years Active: Since 2023
Currently selling public stubs for $69.90 and private stubs for $150
Payload obfuscation and packing
Claims Microsoft Defender evasion, multi-format payload generation (EXE, VBS, PDF, Office documents, scripts, shortcuts, CPL, SCR, BAT, and others), clean and pre-tested loader stubs, and Telegram-based customer support
Years Active: Since 2009
Pricing: Provides a one-time crypt for $30
Years Active: Since October 2025
Currently offers the following plans, priced on capabilities provided:
Years Active: Since April 2025
Pricing: Currently offers the following plans:
Web-based payload crypting and packing service with private loader stub; support for VBS, BAT, and JS payloads; claims Microsoft Defender evasion
Provides subscription-based access (weekly/monthly/private plans) and private customer support
Years Active: Since July 2025
Offers a tiered crypting service based on the capabilities provided per crypt:
Claims Microsoft Defender evasion capabilities
Crypting and packing of EXE, DOC, and PDF files, and support for automatic payload execution via autorun
Years Active: Since February 2026
Implements a tiered subscription service based on the number of files submitted and additional capabilities:
Years Active: Since 2021
Uses a tiered monthly subscription with pricing based on capabilities:
Years Active: Active from April 2025 to October 2025
Provides crypts based on added payload capabilities from $225 to $475
Years Active: Since 2016
Tiered pricing, with rates starting at $30 for one crypt and up to $1,150 for 40 crypts per day over a month
Years Active: Since 2022 (no activity since October 2025)
The threat actor provides a tiered crypting service based on the volume of crypted APKs over a specific time period:
Open-source reporting suggests a possible direct relationship between hiddenroot and BianLian developers.
Years Active: Active for six years
The threat actor provides their services in multiple ways, including one-time crypts, a tiered monthly subscription, custom private packages, and additional payload add-ons:
One-Time Crypt: $1,000
Monthly Subscription Options:
Custom Private Deals (Premium Packages):
Years active: October 2023–current
Pricing: Provides crypted builds for a standardized $40 in BTC, ETH, Litecoin (LTC), and USDT
Automated Telegram-bot crypter for protecting/encrypting .exe files across x86, x64, native, and .NET 2.0/3.5/4.0 targets
Unique per-build encryption using a stub, with claimed 80–91% output variation, fast processing, weekly runtime updates, and AV/AMSI evasion
Stealth and execution features, including startup persistence with termination resistance, decoy/secondary-file execution, anti-analysis environment checks, and custom icon replacement/copying
Technical requirements and qualifications, including .7z delivery, /lastscan AV-result checks, Telegram upload-size limits, and exclusions for drivers, PyInstaller-built EXEs, files that modify startup/restart themselves, or files already packed/protected
Years Active: December 15, 2025–current
Pricing: The threat actor implements a tiered access system, providing additional capabilities at each tier:
Automated crypter/build service with 24/7 generation through a web portal and REST API, supporting .NET Framework, .NET Core/.NET 5–8, and native x86/x64 Windows payloads
Per-build polymorphism and payload protection, including AES-256 encryption, in-memory runtime decryption, compression, junk-code insertion, string encryption, and claimed multi-week FUD duration
AV/EDR evasion claims, including real-time bypass updates, weekly development updates, AMSI/ETW-related evasion, syscall-based techniques, and claimed bypasses for major consumer AV and EDR products
Malware-like execution features, including anti-VM/debug/sandbox checks, sleep obfuscation, multiple injection/loading techniques, UAC-bypass chains, and broad persistence options across registry, startup, services, scheduled tasks, WMI, DLL/COM hijacking, and other Windows mechanisms
Technical requirements and qualifications, including Windows 7–11 compatibility, support for payloads up to 50 MB, Telegram-based support, and cryptocurrency-based purchasing
Years Active: Since 2025
Pricing: The threat actor implements a pay-per-file encryption rate, with the following rates:
Modular .NET crypter/stub-generation service using a custom “USG” pipeline that combines in-house mutators with enterprise obfuscators to produce unique per-client builds
Heavy per-build transformation claims, including multi-stage code rewriting, regenerated metadata/GUIDs/versions/attributes, legitimate-app icon/structure copying, file-size and entropy modification, custom timers, operation-order changes, and unique mutexes
AV/EDR and static-detection evasion claims, including months-long “static life,” resistance to universal signatures, and claimed bypasses for products such as Microsoft Defender, Kaspersky, ESET, CrowdStrike, and SentinelOne
Anti-analysis and sandbox-evasion features, including hypervisor/timing checks, sandbox artifact detection, behavioral trap detection, hardware/system fingerprinting, monitoring process/driver/hook checks, and fallback to benign-looking behavior or clean exit
Runtime and network stealth features, including isolated execution, post-run artifact cleanup, memory-dump resistance claims, HTTPS/CDN/cloud-storage delivery, legitimate-traffic blending, and automatic channel failover
Technical requirements and qualifications include a preference for clean, unpacked files over UPX-, Themida-, or VMProtect-protected inputs; Windows compatibility, including newer builds; special handling for Memory Integrity; interest in testing loaders, droppers, and signed/EV-certificate files; and active “combat” projects
Years Active: Since October 2025
Pricing: The threat actor implements a tiered system based on the number of files that need crypting:
Subscription-based crypter service focused on Windows Defender detection evasion, with tiered seven-day access plans and daily crypt/build quotas
Build workflow features, including a test-file option, fast turnaround, and claimed support for the most popular malware/software families
Service and support terms, including 24/7 technical support, partial refund claims for incompatible or non-connecting software, and Telegram/Tox channels
Years Active: Since June 8, 2025
Pricing: The threat actor implements a tiered system based on the number of files that need crypting:
Automated bot-based crypter that encrypts native x64 files
Subscription-style weekly access model with tiered daily crypt/build limits and a free test-credit option for file compatibility checks
Workflow and qualification details, including bot-command access, compatibility testing against user-provided files/traffic, and quota-based build generation
Years Active: Since September 2025
Pricing: The threat actor implements a tiered system based on the number of files needed to crypt and additional capabilities:
Metamorphic crypter service claiming unique per-file builds for both .NET and native payloads
Detection-evasion claims, including Windows Defender, SmartScreen, runtime, scantime FUD, and broad AV bypass
Positioned as a payload-protection layer intended to make otherwise detectable tools harder to identify before or during execution
Years Active: Since November 2021
Pricing: Last valued publicly at $55 per build in November 2025
Private crypter-panel service offering unlimited crypts over fixed subscription periods, with custom stubs tailored to submitted payloads
Detection-evasion claims, including Windows Defender, SmartScreen, Chrome/Edge/Firefox warning bypasses, long-duration FUD, and EV-certificate-based signing claims
Payload and output support, including native dependency-free output for .NET and C++ x86/x64 files, with examples framed around common malware families
Customization options, including payload-specific stub tuning and optional startup capability, were added by request
Technical requirements and qualifications, including clean submitted files without built-in install/startup/registry-copy behavior, explicit requests for added persistence features, and Telegram/web-panel-based purchase and support
Years Active: Since December 19, 2024
The threat actor provides a tiered service, based on capabilities provided per crypt:
Tiered crypter/stub service offering basic, standard, enhanced, private, PDF-based, MSI, launcher, captcha, mass-mailing, direct-link, and .lnk/.bat packaging options
Detection-evasion claims, including FUD output, SmartScreen avoidance, Windows Defender resistance, VirusTotal FUD claims, EV-certificate signing/copy options, and twice-daily stub updates for the basic tier
Payload wrapping and delivery formats, including basic obfuscation/in-memory loader wrapping, internet-download/exploit/landing-page use cases, PDF-to-.lnk launch flows, MSI installer-style execution, captcha-embedded commands, mass-mailing links, and hosted direct-link delivery
Customization and technical requirements, including native or .NET private stubs, optional splash-screen launcher themes, user-supplied images/templates/icons, archive distribution for EV-certificate builds requiring DLLs, and VPS requirements using Ubuntu 22.04/24.04 or Windows Server 2012 R2
Below is a table that contains the full MITRE ATT&CK Enterprise mappings associated with the behaviors demonstrated across the crypting services that Insikt Group analyzed.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
