Recorded Future's Insikt Group identified a competitive underground market of at least 24 active malware crypting service providers selling tools that modify malicious payloads to evade antivirus and endpoint defenses. The offerings are marketed across underground forums, restricted communities, messaging platforms, clearnet sites, and social media, with most focused on Windows payloads and advertising bypasses for Microsoft Defender, SmartScreen, AMSI, ETW, Chrome warnings, and broader AV/EDR controls.
The services go beyond basic packing or encryption and increasingly bundle broader malware-enablement features, including in-memory execution, anti-VM and anti-sandbox checks, process injection, persistence, delivery packaging, polymorphic or per-build stubs, and re-crypting after detection. Sellers support formats such as EXE, DLL, .NET, scripts, Office files, PDFs, MSI packages, APKs, and shortcut-based launchers, with pricing ranging from tens of dollars to tens of thousands; while most vendors show no confirmed ties to malware developers, some listings suggest possible links to actors or families including TrickBot, Conti, Agent Tesla, PureRAT, and BianLian, underscoring how established defense-evasion techniques are being commercialized for wider criminal use.

TTPs, infrastructure, and targeting history in one profile.
13 events from the most recent confirmed update back to the earliest known activity.
Insikt Group published analysis of 24 crypting-service providers active within the past year, describing a competitive malware-enablement market centered largely on Windows payloads and broader defense-evasion capabilities.
Recorded Future published research cataloging underground crypter and packer sellers, their pricing, claimed evasion features, supported payload formats, and possible malware-family affiliations.
A seller active since February 2026 began offering subscription tiers from $80 for three files to $700 for 50 files, advertising personalized encryption and extended detection evasion.
Recorded Future says a seller active since October 2025 began offering Shared Cruciferra, Purosangue AV-Killer, and Coconut Single Executable plans with claims of Defender and Chrome bypass, AV process termination, and persistence protection.
A seller active from April 2025 to October 2025 offered EXE and DLL crypts priced from $225 to $475 and claimed Defender and SmartScreen evasion; open-source data suggested a relationship with PureRAT.
A July 2025 eSentire report associated the PureRAT RAT and GhostCrypt crypting service with the earlier attack on a public US accounting firm.
Recorded Future describes a seller active since July 2025 that offered Standard, Private, and Premium crypting tiers priced at $60, $80, and $100, and notes possible ties to AURA Stealer based on forum posts.
The Malware News summary cites an eSentire report associating the PureRAT remote access trojan and GhostCrypt crypting service with an attack that impacted a public US accounting firm in May 2025.
A seller active since April 2025 began offering web-based payload crypting and packing for VBS, BAT, and JS payloads, with plans ranging from one week to three months.
Recorded Future says another seller became active in 2023, advertising public stubs for $69.90 and private stubs for $150 with Defender evasion and Telegram support.
A seller focused on APK obfuscation was described as active since 2022, offering tiered pricing for daily Android package crypting services.
One profiled seller was described as active since 2021, offering a normal crypter for $500 and a crypter bundled with an EV certificate for $2,500.
The Recorded Future profile states Bentley was active from 2020 to 2023 selling crypts, and leaked Conti chats implicated Bentley as officially affiliated with TrickBot and involved in developing and administering Conti.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
3 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcemalware.news
Open sourcerecordedfuture.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.