Sophos linked thousands of malware samples to HeartCrypt, a packer-as-a-service operation that tampered with legitimate executables and DLLs by inserting position-independent loader code and encrypted payloads. The activity spanned countries in every hemisphere and impersonated more than 200 software vendors, with nearly 1,000 command-and-control servers observed; Colombia appeared to be among the most heavily affected locations. Infection chains varied widely, including phishing emails, DLL sideloading, LNK and PowerShell downloaders, and password-protected archives distributed through cloud services such as Google Drive and Dropbox.
The packed malware most often delivered commodity stealers and remote-access tools including Lumma Stealer, AsyncRAT, and Rhadamanthys, but Sophos also found AVKiller payloads tied to ransomware intrusions involving RansomHub and MedusaLocker. Researchers said HeartCrypt used obfuscation, anti-emulation checks, and XOR-encrypted payloads with static ASCII keys, then established persistence by copying oversized files and launching them through Windows Run keys or rundll32. Sophos assessed the operation was not the work of a single threat actor, but a shared criminal service used by multiple groups with different payloads, techniques, and regional targets.

TTPs, infrastructure, and targeting history in one profile.
2 events from the most recent confirmed update back to the earliest known activity.
Based on varied infection chains, payloads, and targeting patterns, Sophos assessed HeartCrypt is not attributable to a single actor such as Blind Spider but is instead a shared service used by multiple threat actors. Observed payloads included commodity RATs and stealers as well as AVKiller payloads linked to ransomware activity involving RansomHub and MedusaLocker.
Sophos analyzed thousands of malware samples and concluded they were tied to HeartCrypt, a packer-as-a-service operation used to modify legitimate executables and DLLs with loader code and encrypted payloads. The analysis found nearly 1,000 C2 servers, more than 200 impersonated software vendors, and global targeting, with Colombia appearing especially affected.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 31 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.