HeartCrypt: A Packer-as-a-Service Fueling Malware Campaigns
ID: c291be03-8bec-5d48-bc26-f90f57767ae7
STIX ID: report--c291be03-8bec-5d48-bc26-f90f57767ae7
Feed Name: securityonline.info
Unit 42 reveals HeartCrypt, a Packer-as-a-Service launched in February 2024 that has packed over 2,000 malicious payloads across 45 malware families; the low-cost service ($20 per file) is advertised on Telegram and cybercrime forums and enables widespread use of advanced obfuscation (injection into legitimate binaries, control-flow obfuscation, layered encryption) plus sandbox/AV/VM evasion, and has been used to distribute families such as LummaStealer, Remcos, and Rhadamanthys.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
