HeartCrypt is a Windows packer-as-a-service (PaaS) crypter, developed from at least 2023 and publicly marketed from early 2024, that is used by multiple financially motivated threat actors to obfuscate and deliver malware. It has been used to pack thousands of payloads across dozens of malware families, including commodity information stealers, remote-access trojans, ransomware-adjacent loaders, and endpoint-security killer tooling. HeartCrypt activity has been associated with phishing campaigns, including regionally tailored social-engineering lures, and has affected organizations globally, with reported campaigns targeting Latin America and Colombian institutions. APT-C-36, also known as Blind Eagle, has used HeartCrypt alongside commodity RATs and other crypters.
HeartCrypt modifies legitimate Windows executables or DLLs by injecting position-independent loader code, redirecting execution flow, and embedding encrypted payloads in PE resources masquerading as image data. Its loader employs code obfuscation, dynamic API resolution, junk instructions, anti-sandbox and anti-emulation checks, and payload decryption to impede analysis and detection. It identifies whether its embedded payload is managed or native and uses process hollowing to execute it within legitimate or copied Windows processes. Some variants establish persistence by copying an inflated version of themselves and configuring automatic execution through Windows startup mechanisms. HeartCrypt is a shared commercial obfuscation service rather than malware attributable to one operator; it has also been used to conceal EDR-killer components deployed before ransomware execution.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
APT-C-36 has utilized well known malware including the Packer-as-a-Service HeartCrypt, PureCrypter, and open-source RATs such as Remcos.
In many cases, packer-as-a-service offerings such as HeartCrypt are used to obfuscate the tools.
We ultimately concluded that these cases were all connected to what has come to be known as the HeartCrypt packer-as-a-service (PaaS) operation.
31 distinct techniques documented for this family, organized by ATT&CK tactic.
The process trace indicates that the initial infection could be related to the zero-day RCE exploits... which affected ConnectWise and BeyondTrust products.
This infection chain starts with a phishing email... This email claims to be from an Italian lawyer contacting the recipient about alleged copyright infringement... The malicious content was hosted on a Google Drive in a password-protected ZIP archive; the password was included in the phishing email.
This PowerShell command downloads and executes another PowerShell script... This script downloads two further files.
To modify the registry, HeartCrypt uses either Windows API functions or the reg add command via cmd.exe.
Secondly, HeartCrypt hijacks the control flow within the original binary. This is most often achieved by altering the start() function, the entry point for many executables. The modification typically involves adding a call or jmp instruction which redirects execution to the newly added PIC.
To modify the registry, HeartCrypt uses either Windows API functions or the reg add command via cmd.exe.
the code uses API functions such as CreateProcessW... to load and execute the final payload.
the code uses API functions such as CreateProcessW, VirtualAlloc, GetThreadContext, NtCreateThreadEx, and CreateRemoteThread to load and execute the final payload.
While process hollowing is the primary method of injection, we have identified a sample that references NtQueueApcThread, suggesting that the developer has invested effort into diversifying the injection methods.
Agent Tesla has used process hollowing to create and manipulate processes through sections of unmapped memory by reallocating that space with its malicious code. APT-C-36 has used process hollowing to execute malware in the memory of legitimate processes. Astaroth can create a new process in a suspended state from a targeted legitimate process in order to unmap its memory and replace it with malicious code.
the code uses API functions such as CreateProcessW... to load and execute the final payload.
The injected PIC leverages multiple control flow obfuscation methods to hinder analysis. These include: Stack strings Dynamic API resolution Hundreds of direct jmp instructions Non-returning functions Arithmetic operations that have no effect on program execution Junk bytes after jmp and call instructions, impeding disassembly and decompilation
HeartCrypt was originally discovered through underground forums... it has been used to pack over 2,000 malicious payloads... The packed payload was consistently added as a resource to a legitimate binary... Each resource embedded in the binary contains PIC disguised as a bitmap (BMP) image file. This begins with a standard BMP header followed by a repeating hexadecimal pattern for padding.
The injected PIC leverages multiple control flow obfuscation methods to hinder analysis. These include: Stack strings Dynamic API resolution...
Encrypted malicious payloads inserted as an additional resource... It also inserts a few additional Portable Executable (PE) resources. These resources are disguised as bitmap files and start with a BMP header, but afterwards the malicious content follows.
Malware impersonating, subverting, and embedding itself in legitimate software applications... The HeartCrypt packer takes legitimate executables and modifies them by injecting malicious code in the .text section.
the code uses API functions such as CreateProcessW, VirtualAlloc, GetThreadContext, NtCreateThreadEx, and CreateRemoteThread to load and execute the final payload.
While process hollowing is the primary method of injection, we have identified a sample that references NtQueueApcThread, suggesting that the developer has invested effort into diversifying the injection methods.
Agent Tesla has used process hollowing to create and manipulate processes through sections of unmapped memory by reallocating that space with its malicious code. APT-C-36 has used process hollowing to execute malware in the memory of legitimate processes. Astaroth can create a new process in a suspended state from a targeted legitimate process in order to unmap its memory and replace it with malicious code.
When it finds it, it loads the driver and terminates the processes and services from the target list... It also attempts to kill processes such as MsMpEng.exe, SophosHealth.exe, SAVService.exe, and sophosui.exe.
The fourth resource decrypts and injects the final payload... The payload is a Windows executable binary encoded via a single-byte XOR operation rotating over a key hard-coded in the resource PIC as a stack string. After decryption, the PIC parses the decoded PE header...
the DLL file as a standalone component... is copied to C:\Users\{user}\OneDrive\Documents\AvivaUpdate_0001.dll... and registered for startup with the following command line: rundll32.exe C:\Users\{user}\OneDrive\Documents\AvivaUpdate_0001.dll,EntryPoint
Resource 1: Anti-Dependency Emulation... attempts to load non-existent DLLs via LoadLibraryW... If the sandbox responds by generating a dummy DLL... HeartCrypt will call ExitProcess... Resource 2: Sandbox Loop Emulation Check... If this flag is not set, the process will call ExitProcess. Resource 3: Windows Defender Evasion... If HeartCrypt can load this API from kernel32, it can assume the sample is running within the Defender emulator.
Secondly, HeartCrypt hijacks the control flow within the original binary. This is most often achieved by altering the start() function, the entry point for many executables. The modification typically involves adding a call or jmp instruction which redirects execution to the newly added PIC.
Here we see a DynamicShellcode alert... The process trace revealed that the malicious killer was executed from the JWrapper-Remote Access component of SimpleHelp
The resource enters a while loop that performs a large number of mathematical calculations on an initial hard-coded value... The resulting hash is checked against an expected value. If the two values match, the sample will set a flag value within memory to indicate the loop was not emulated or modified in any way. If this flag is not set, the process will call ExitProcess.
It then proceeds to create a run key in the \SOFTWARE\Microsoft\Windows\CurrentVersion\Run registry location.
Resource 1: Anti-Dependency Emulation... attempts to load non-existent DLLs via LoadLibraryW... If the sandbox responds by generating a dummy DLL... HeartCrypt will call ExitProcess... Resource 2: Sandbox Loop Emulation Check... If this flag is not set, the process will call ExitProcess. Resource 3: Windows Defender Evasion... If HeartCrypt can load this API from kernel32, it can assume the sample is running within the Defender emulator.
The resource enters a while loop that performs a large number of mathematical calculations on an initial hard-coded value... The resulting hash is checked against an expected value. If the two values match, the sample will set a flag value within memory to indicate the loop was not emulated or modified in any way. If this flag is not set, the process will call ExitProcess.
ABYSSWORKER provides handlers to "terminate or permanently disable EDR systems," including removing notification callbacks, replacing driver major functions, detaching MiniFilter devices, killing system threads, and restoring NTFS/PNP driver functions.
In today’s multi-stage attacks, neutralizing endpoint security solutions is a critical step in the process, allowing threat actors to operate undetected. Since 2022, we’ve seen an increase in the sophistication of malware designed to disable EDR systems on an infected system.
31 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A packer-as-a-service tool used to pack payloads and inject malicious code into legitimate binaries during malware development/compilation.
Packer used to protect the loader component of AbyssKiller, adding obfuscation and anti-analysis capabilities.
Packer-as-a-service malware used to deliver stealers, RATs, and AVKiller, distributed via phishing emails and LNK files.
A previously popular packer-as-a-service offering used by ransomware groups.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.