GhostCrypt is a criminal malware crypting service and underground operator associated with payload obfuscation and defense-evasion support for Windows malware. It has been advertised under the aliases GhostCrypt and ghost_crypt. Rather than functioning as a standalone intrusion set, GhostCrypt operates as a malware-enablement provider that helps other threat actors modify malicious payloads to reduce antivirus and EDR detection, complicate analysis, and preserve malware usability after exposure. Reported service characteristics align with the broader crypter market, including payload wrapping, in-memory execution support, anti-analysis checks, process injection, persistence-related options, and re-crypting after detection. GhostCrypt has been linked to PureRAT activity, including an intrusion affecting a U.S. accounting firm in 2025. Its role is best understood as a financially motivated cybercriminal service provider that supports downstream malware operations by improving stealth and execution success rather than conducting the full intrusion lifecycle itself.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
1 malware family attributed to this actor across reporting.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An underground crypting service associated with PureRAT and linked in reporting to an attack affecting a US accounting firm.
Ghost Crypt is associated with powering the PureRAT malware, possibly using a component or technique called Hypnosis, suggesting involvement in remote access trojan operations.
Ghost Crypt is powering the PureRAT malware with a component called Hypnosis.
Ghost Crypt is powering the PureRAT malware with a component called Hypnosis.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.