FUD Crypt: New Malware-as-a-Service Generates Microsoft-Signed Malware
Severity: High (Score: 61.5)
Sources: Gbhackers, Cybersecuritynews
Summary
A new platform called FUD Crypt is enabling cybercriminals to create sophisticated, Microsoft-signed malware without coding. This Malware-as-a-Service (MaaS) offers a service where users can upload any Windows executable, which is then transformed into a polymorphic malware package. The service operates from fudcrypt.net and charges monthly fees ranging from $800 to $2,000. The malware generated can install persistence and connect to a command-and-control (C2) platform, making it difficult to detect. The ease of use and the ability to produce undetectable malware pose significant risks to Windows systems. As of now, there are no specific CVEs associated with this service, but its implications for cybersecurity are profound. Organizations using Windows systems are particularly at risk due to the nature of the malware produced. Key Points: • FUD Crypt allows users to create undetectable Microsoft-signed malware easily. • The service charges between $800 and $2,000 per month for its offerings. • Windows systems are at high risk due to the polymorphic nature of the malware.
Key Entities
- Malware (attack_type)
- fudcrypt.net (domain)
- T1071 - Application Layer Protocol (mitre_attack)
- Windows (platform)
- FUD Crypt (tool)