logo

Microsoft-Signed Malware Built With FUD Crypt Packs Persistence and C2

ID: b5fd787f-0986-5c99-a954-bb794b8eae22

STIX ID: report--b5fd787f-0986-5c99-a954-bb794b8eae22

Feed Name: GBHackers

Threat Score
88/100

Date Published: 2026-04-20

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

The report describes FUD Crypt, a commercial Malware‑as‑a‑Service that uses Azure Trusted Signing to produce Microsoft‑chained Authenticode binaries which evade detection, establish persistence (Run key and scheduled task), bypass AMSI/ETW and UAC, and connect to a WebSocket C2 (mstelemetrycloud.com). Investigators observed active deployments (32 agents, many with admin privileges) and thousands of issued commands; the platform includes per‑build AV tuning, DLL sideloading into legitimate apps, and features to disable Defender and deploy remote access tools, making it a high‑risk, highly evasive malware distribution service.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.