Researchers linked HCrypt, an active crypter-as-a-service, to a multi-stage malware chain that delivered the BitRAT remote access trojan through obfuscated HTA, JavaScript, VBScript, and PowerShell stages. In the analyzed sample, an HTA launcher fetched additional payloads from 135.148.74[.]241, modified the HKCU\Explorer\User Shell Folders\Startup registry value for persistence, and dropped another HTA under C:\ProgramData\3814364655181379114711 before moving to in-memory execution.
The final PowerShell stage decoded two embedded PE files from hex, loaded a .NET injector DLL in memory, and invoked the HH.HH.HHH method to inject the payload into aspnet_compiler.exe. The injector used Windows API functions including LoadLibraryA and GetProcAddress, while the second decoded binary was identified as a UPX-packed BitRAT sample that matched BitRAT YARA signatures after unpacking. The reporting indicates that HCrypt and similar commodity crypters have made process injection a routine capability for malware operators, helping commodity malware evade detection and complicate forensic analysis.

Pull IOCs and campaign context straight into your stack.
1 event from the most recent confirmed update back to the earliest known activity.
A blog post analyzed an HTA-based, multi-stage malware chain in which obfuscated scripts launched PowerShell, downloaded additional stages from 135.148.74[.]241, established persistence, and used a .NET injector associated with HCrypt to inject a BitRAT payload into aspnet_compiler.exe. The analysis identified the final payload as UPX-packed BitRAT based on YARA matches and documented indicators including the injector assembly GUID and payload hashes.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.