logo

HeartCrypt: A Packer-as-a-Service Fueling Malware Campaigns

ID: c291be03-8bec-5d48-bc26-f90f57767ae7

STIX ID: report--c291be03-8bec-5d48-bc26-f90f57767ae7

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2024-12-17

Date Updated: 2026-04-22

Author: do son

...
...

Unit 42 reveals HeartCrypt, a Packer-as-a-Service launched in February 2024 that has packed over 2,000 malicious payloads across 45 malware families; the low-cost service ($20 per file) is advertised on Telegram and cybercrime forums and enables widespread use of advanced obfuscation (injection into legitimate binaries, control-flow obfuscation, layered encryption) plus sandbox/AV/VM evasion, and has been used to distribute families such as LummaStealer, Remcos, and Rhadamanthys.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.