SonicCrypt is a C++ crypter/packer used as malware-as-a-service to hinder analysis and detection by decrypting and loading other malware prior to execution. Proofpoint reported it is often used to pack MonsterV2, and that MonsterV2 may be decrypted and loaded via SonicCrypt. Observed SonicCrypt behavior includes anti-analysis and environment checks, including checks of system RAM and BIOS data, before decrypting the payload. It can execute the decrypted payload via Windows Task Scheduler COM, specifically CLSID_TaskScheduler. In the reported activity, SonicCrypt was associated with campaigns involving MonsterV2, a RAT/stealer/loader used by TA585 and other actors. The content does not provide independent infection vectors, victimology, or standalone IOCs for SonicCrypt beyond its role as a crypter used to protect and launch payloads.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware-as-a-service packer used to obfuscate/protect payloads (notably MonsterV2) to hinder analysis and detection.
C++ crypter/packer used to pack MonsterV2 and perform anti-analysis checks prior to decrypting/loading the payload.
C++ crypter/packer used to protect MonsterV2. Performs environment/anti-analysis checks (e.g., RAM/BIOS), may add Defender exclusions and bypass UAC, drops a decrypted payload to disk (e.g., WinHealth.exe/WindowsSecurity.exe) and executes it via Task Scheduler (CLSID_TaskScheduler).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.