ScrubCrypt is a commercially available crypter used in commodity cybercrime operations to obfuscate and deliver additional malware. Active since at least 2023, it has been observed in campaigns involving infostealers and cryptominers, and has been linked to financially motivated threat activity including operations attributed to 8220 Gang. ScrubCrypt has been sold on underground marketplaces and used as part of multi-stage infection chains to reduce detection and install follow-on payloads.
ScrubCrypt has been implemented as a .NET-based crypter and has also appeared as heavily obfuscated script-based variants, including batch-script loaders. Observed variants decode, decrypt, and launch embedded payloads, sometimes entirely in memory, and can act as an installation layer for other malware families. Reported follow-on payloads include RedLine Stealer, XMRig, and XWorm. In some intrusion chains, ScrubCrypt has been used together with process injection into legitimate Windows processes to execute subsequent stages while evading analysis and endpoint defenses.
Delivery has been observed through exploitation of internet-facing enterprise software vulnerabilities, including Oracle WebLogic flaws and Log4Shell against VMware Horizon environments. It has also been associated with fraud and account-takeover activity involving RedLine Stealer. In analyzed loader chains, ScrubCrypt-obfuscated scripts were dropped and executed by an initial loader, then extracted and decrypted embedded payloads for execution.
ScrubCrypt primarily serves as an obfuscation and payload-delivery layer rather than as the final objective malware. Its role in campaigns is to conceal malicious code, bypass static detection, and facilitate execution of secondary malware on compromised Windows systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Ahnlab Security Emergency response Center (ASEC) has recently confirmed that the 8220 Gang attack group is using the Log4Shell vulnerability to install CoinMiner in VMware Horizon servers. Log4Shell (CVE-2021-44228) is both a remote code execution vulnerability and the Java-based logging utility Log4j vulnerability... | Fortinet recently revealed a case where 8220 Gang installed ScrubCrypt by exploiting Oracle Weblogic server vulnerabilities. ScrubCrypt is a Crypter developed as .NET and provides a feature to install additional malware.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Fortinet recently revealed a case where 8220 Gang installed ScrubCrypt by exploiting Oracle Weblogic server vulnerabilities. ScrubCrypt is a Crypter developed as .NET and provides a feature to install additional malware.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
ASEC has confirmed a log where the recently vulnerable ws_tomcatservice.exe process installed the CoinMiner malware... judging from the attack log where the PowerShell command was executed by VMware Horizon’s ws_tomcatservice.exe process
If the CVE-2022-26134 vulnerability attack succeeds, the following PowerShell command downloads and executes additional PowerShell scripts and ultimately installs XMRig CoinMiner.
“bypass.ps1” is an obfuscated PowerShell script... “PhotoShop-Setup-2545.exe” is a .NET downloader malware that downloads and decodes encoded data... The malware injected in the RegAsm process and executed is obfuscated
12 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
ScrubCrypt is used as an obfuscating crypter layer in the infection chain. In this sample it drops/extracts, decrypts, and loads the embedded XWorm .NET assembly using heavily obfuscated batch logic, self-referencing via %~f0, and extensive environment-variable manipulation.
An obfuscation tool used in conjunction with RedLineStealer campaigns to help deliver attacks involving account takeover and fraud.
A .NET crypter/downloader used by 8220 Gang to fetch commands from C2 and install additional payloads, ultimately leading to XMRig deployment. It injects payloads into processes such as RegAsm.exe and MSBuild.exe.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.