logo

Crypted Hearts: Exposing the HeartCrypt Packer-as-a-Service Operation

ID: 233f3a42-30ac-56c1-a133-155af3f24a65

STIX ID: report--233f3a42-30ac-56c1-a133-155af3f24a65

Feed Name: Palo Alto Networks Unit 42

Threat Score
78/100

Date Published: 2024-12-13

Date Updated: 2026-04-28

Author: Jerome Tujague and Daniel Bunce

...
...

Unit42 analyzes HeartCrypt, a packer‑as‑a‑service (PaaS) that has been used since mid‑2023 to obfuscate and distribute malware by injecting multi‑layer position‑independent code and encoded payloads into legitimate Windows binaries; HeartCrypt (publicly marketed since Feb 2024) has packed over 2,000 payloads across ~45 malware families (notably Remcos, LummaStealer and Rhadamanthys), employs resource‑based execution, sandbox and Windows Defender evasion, and lowers the barrier for crimeware operators—report includes detailed technical breakdowns, automated extraction techniques, a YARA rule and IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.