Microsoft-Signed Malware Built With FUD Crypt Packs Persistence and C2
ID: b5fd787f-0986-5c99-a954-bb794b8eae22
STIX ID: report--b5fd787f-0986-5c99-a954-bb794b8eae22
Feed Name: GBHackers
The report describes FUD Crypt, a commercial Malware‑as‑a‑Service that uses Azure Trusted Signing to produce Microsoft‑chained Authenticode binaries which evade detection, establish persistence (Run key and scheduled task), bypass AMSI/ETW and UAC, and connect to a WebSocket C2 (mstelemetrycloud.com). Investigators observed active deployments (32 agents, many with admin privileges) and thousands of issued commands; the platform includes per‑build AV tuning, DLL sideloading into legitimate apps, and features to disable Defender and deploy remote access tools, making it a high‑risk, highly evasive malware distribution service.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
