Cryptoistic is a Lazarus Group-associated malware family documented as supporting command-and-control over TCP with encrypted communications. Reported functionality includes collecting user information from compromised hosts, retrieving files from local file systems, and deleting files on infected systems, indicating a combination of reconnaissance, collection, exfiltration support, and anti-forensic cleanup behavior. It has been referenced alongside other Lazarus-linked malware families used in North Korean state-sponsored operations targeting sectors such as finance, cryptocurrency, defense, software, pharmaceuticals, manufacturing, and related industries. Based on the available facts, Cryptoistic is best characterized as a backdoor-oriented implant used for post-compromise host interaction and data handling on Windows systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Related Malware: AppleJeus BADCALL Bankshot BLINDINGCAN Cryptoistic Dtrack KEYMARBLE KiloAlfa SierraAlfa ThreatNeedle Torisma WannaCry
8 distinct techniques documented for this family, organized by ATT&CK tactic.
Andariel has collected large numbers of files from compromised network systems for later extraction... APT28 has retrieved internal documents from machines inside victim environments... BADNEWS crawls the victim's local drives and collects documents... many listed groups and malware collect files, documents, credentials, payment card data, or other information from compromised hosts.
The content repeatedly describes malware and threat actors that can "download files from C2," "download additional payloads," "upload and download files," "retrieve payloads from the C2 server," and "copy files to remote machines."
“APT29 has used multiple layers of encryption within malware to protect C2 communication… BITTER has encrypted their C2 communications… MacMa has used TLS encryption… Magic Hound has used an encrypted http proxy in C2 communications… gh0st RAT has encrypted TCP communications…”
“APT29 has used multiple layers of encryption within malware to protect C2 communication… BITTER has encrypted their C2 communications… Emotet has encrypted data before sending to the C2 server… gh0st RAT has encrypted TCP communications to evade detection… Gomir uses a custom encryption algorithm…”
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware that gathers data on the user of a compromised host.
Lazarus-associated malware family listed as related malware.
Gathers data on the user of a compromised host.
Malware that retrieves files from the local file system.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.