Ghost Crypt is a Windows malware crypter offered as a crypter-as-a-service and observed in active delivery chains for multiple commodity malware families, including XWORM. It has been used in campaigns that package a legitimate PDF reader with a malicious DLL to exploit DLL sideloading, causing the trusted application to load Ghost Crypt when a victim opens a decoy document. After execution, Ghost Crypt deploys the next-stage payload using a process injection method described as "process hypnosis," creating a target process in a debug state, allocating memory in that process, writing the payload into it, and resuming execution so the final malware runs under the context of a legitimate Windows process. Reported campaigns also established persistence through a user Run key that launches a copied DLL via rundll32. Ghost Crypt functions primarily as an obfuscation and delivery layer rather than the final payload itself, enabling operators to wrap and inject remote-access trojans and stealers while complicating detection and analysis.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
The technique consists of creating a process with the CreateProcessW API together with the DEBUG_ONLY_THIS_PROCESS flag.
the DLL's entry point is set as a "run" registry key by the following command: cmd.exe /C reg add "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "CriticalUpdater3" /t REG_SZ /d "rundll32.exe \"C:\Users\arcana\Documents\Sensor57380.dll\",EntryPoint" /f & exit
Ghost Crypt uses a technique called Process Hypnosis to inject the final payload into csc.exe (a Visual C# compiler), leveraging Windows APIs to stealthily execute the malware.
The technique consists of creating a process with the CreateProcessW API together with the DEBUG_ONLY_THIS_PROCESS flag.
the DLL's entry point is set as a "run" registry key by the following command: cmd.exe /C reg add "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "CriticalUpdater3" /t REG_SZ /d "rundll32.exe \"C:\Users\arcana\Documents\Sensor57380.dll\",EntryPoint" /f & exit
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Crypter-as-a-service used to deliver malware via a zipped archive containing a legitimate PDF reader app, a DLL, and a PDF; opening the PDF triggers DLL side-loading to initiate malware execution.
A malware delivery/crypter service publicized on HackForums that exploits DLL side-loading in known applications, uses 'Process Hypnosis' to inject payloads into csc.exe, and delivers final malware payloads such as XWORM.
Malware crypter observed in the wild (per eSentire), used to obfuscate/protect other malware payloads.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.