TangleCrypt is a previously undocumented Windows malware packer observed in a September 2025 Qilin ransomware attack. It was used to conceal malicious payloads, including the STONESTOP EDR killer, and supported a bring your own vulnerable driver (BYOVD) attack using the ABYSSWORKER driver. Reporting indicates it uses multiple layers of encoding and compression to hide payloads, although manual unpacking was described as relatively straightforward. Public reporting also noted coding flaws associated with the operation that caused the ransomware to crash unexpectedly. High-confidence associations in the provided content tie TangleCrypt to Qilin ransomware activity on Windows systems and to payloads intended to disable or evade endpoint detection and response products.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Obfuscation/packing loader that stores payload in PE resources with layered base64, LZ78, and XOR; can launch payload in-process or in a child process; uses basic string encryption and dynamic import resolving; implementation flaws may destabilize payload.
TangleCrypt is a Windows malware packer designed to obfuscate and protect malicious payloads, used in ransomware attacks to evade detection and facilitate payload delivery.
TangleCrypt is discussed as ransomware using a packer to hide an EDR-killing component, though coding flaws reportedly cause it to crash unexpectedly.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.