CryptOne, also known as HellowinPacker, is a malware packer and crypter service used by multiple major cybercrime operations to obfuscate payloads, hinder reverse engineering, and improve antivirus evasion. It has been associated most prominently with Evil Corp activity and has been observed protecting malware and post-exploitation payloads including WastedLocker, Hades-lineage ransomware, Gozi ISFB variants, ZLoader, SmokeLoader, Dridex, Emotet, QakBot, NetWalker, and Cobalt Strike components.
CryptOne operates as a multi-stage loader. A first-stage DLL contains encrypted data that is copied into executable memory and decrypted to reveal shellcode and additional encrypted content. The shellcode then decrypts the final PE payload and reflectively loads it. Reported implementations resolve APIs dynamically, including via kernelbase, unmap the original loader image, map the final payload into memory, repair imports and relocations, adjust section protections, update loader metadata, and transfer execution to the payload entry point.
The packer incorporates several anti-analysis and defense-evasion features. These include entropy-reduction techniques that interleave encrypted data with junk bytes to make packed samples appear less suspicious, simulated sleep implemented through loops of irrelevant code and noisy system calls to exhaust sandbox time limits, misleading or dead code intended to disrupt static analysis, and registry-based killswitch checks that can force the loader into an infinite loop when expected artifacts are absent. Public reporting has also described CryptOne variants that allocate memory, reconstruct encrypted blobs, decrypt them with XOR-based routines, and execute shellcode to launch the protected payload.
CryptOne became notable in 2020 and 2021 as part of Evil Corp’s tooling changes after sanctions pressure and broader operational retooling. It was used to protect WastedLocker and later linked to related ransomware families in the same cluster. Separate reporting also indicates that QakBot previously relied on its own crypters, including CryptOne, before shifting toward other crypter ecosystems. Overall, CryptOne is best understood as a sophisticated criminal packer-as-a-service focused on stealthy in-memory unpacking and anti-analysis rather than as a standalone payload family.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
WastedLocker is protected with a custom crypter, referred to as CryptOne by Fox-IT InTELL.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
29 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A crypter-as-a-service previously used with Qakbot before broader adoption of ITG23-related crypters.
Malware packer/cryptor used to pack multiple malware families; provides sandbox evasion, anti-emulation, and code-flow obfuscation, and is central to linking multiple Evil Corp malware variants.
Custom cryptor associated with WastedLocker that decrypts payloads using an XOR-based algorithm.
Crypter associated with WastedLocker that uses VirtualAlloc to help execute payloads.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.