Asgard Protector is a malware crypter service promoted on the XSS forum since at least 2023 and recommended by sellers of LummaC2. It is used to conceal and deliver malicious payloads while helping them evade antivirus and other security controls. SpyCloud Labs reported that it is used to hide malware including LummaC2/Lumma Stealer, Rhadamanthys, Quasar RAT, and other stealers and malware families. The service advertises itself as an AUTOcrypt offering that generates stubs for submitted malware through a Telegram bot, with customizable crypting options.
Its delivery chain uses Nullsoft installation binaries functioning as self-extracting RAR archives, which extract files into %temp% and execute an obfuscated batch file. Asgard Protector uses mismatched file extensions to disguise components; in one analyzed case, the installer batch file masqueraded as an ASCII text file named Belgium.pst. The batch script performs basic antivirus checks before execution, reconstructs an AutoIt interpreter from data stored in a .cab file plus a hardcoded MZ header, then rebuilds and launches a compiled AutoIt script from remaining disguised files.
The compiled AutoIt component is heavily obfuscated and implements the core payload execution logic. It supports customizable behavior including autorun functionality and an IP logger. The malware payload is embedded encrypted in the AutoIt script, decrypted in memory with RC4, decompressed in memory using RTLDecompressFragment with the LZNT1 algorithm, and injected for execution, typically into explorer.exe. Asgard Protector also performs sandbox detection by pinging randomly generated domains that should not resolve; if a response is received, it exits.
SpyCloud pivoting on VirusTotal identified more than 1,200 related samples and more than 200 protected samples used for usage analysis. Over 69% of identified Asgard Protector-protected samples carried LummaC2, while just over 11% carried Rhadamanthys. Some antivirus products reportedly misclassify Asgard Protector as CypherIT; SpyCloud noted functional similarities that may indicate a possible relationship, but this was not confirmed. Detection-relevant behaviors directly mentioned include extraction to %temp%, execution of obfuscated batch scripts, reconstruction of AutoIt binaries and scripts from disguised files, in-memory RC4 decryption and LZNT1 decompression, injection into explorer.exe, and sandbox checks via ping requests to randomly generated domains.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
9 distinct techniques documented for this family, organized by ATT&CK tactic.
Crypters are tools used by cybercriminals that allow them to hide malicious payloads in seemingly nonmalicious wrappers or “packed” samples, allowing them to easily bypass antivirus (AV) software and other protections.
As observed in Image 2, Asgard Protector leverages mismatched file extensions in order to better hide. The .bat file it looks for is the ASCII text file, or in this sample, Belgium.pst.
Asgard Protector normally injects the malware payload into explorer.exe, which helps the malware to evade detections.
The malware sits encrypted in the AutoIt script and is decrypted in memory using RC4.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Crypter service used to obfuscate and deliver various malware payloads, including stealers and RATs, by injecting encrypted payloads into memory to evade detection.
A malware crypter that packages payloads in Nullsoft installers, reconstructs and runs hidden AutoIt components, decrypts embedded payloads in memory with RC4, decompresses them with LZNT1/RTLDecompressFragment, injects them into explorer.exe, and includes sandbox-evasion and optional features such as autorun and IP logging.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.