Crypt4You is a cybercriminal actor associated with the advertising and sale of VOID KILLER, a kernel-level tool designed to disable antivirus and endpoint detection and response protections on Windows systems. The actor has been observed promoting this capability on underground forums and dark web marketplaces as a serviceable alternative to traditional crypters, indicating a role in the criminal tooling ecosystem rather than a clearly attributed state-sponsored operation. VOID KILLER is positioned as a defense-evasion and post-compromise enabler. Reported capabilities include terminating Windows security products and enterprise EDR solutions, operating with kernel-level privileges, using polymorphic builds to hinder signature-based detection, incorporating automatic User Account Control bypass, and supporting payload-agnostic execution so that other malware can be deployed after security controls are neutralized. These characteristics indicate support for privilege escalation, defense evasion, and post-exploitation workflows, and make the tooling potentially useful to a broad range of financially motivated malware operators. No high-confidence attribution to a specific country, formal intrusion set, or broader umbrella group is currently available. No corroborated victimology or country-specific targeting has been established beyond the tool's applicability against organizations using common consumer and enterprise endpoint protections.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 malware family attributed to this actor across reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.