Verschlüsselte Herzen: Offenlegung des HeartCrypt Packer-as-a-Service-Betriebs

Teilen:
Category Einzelheiten
Threat Actors Unknown actors offering the HeartCrypt PaaS targeting various regions and industries.
Campaign Overview HeartCrypt is a Packer-as-a-Service (PaaS) launched in February 2024, used to protect malware by obfuscating code within legitimate binaries. Advertised in underground forums and Telegram, it supports 32-bit Windows payloads for $20 per file.
Target Regions (Victims) Observed campaigns in Latin America and other global regions. Specific targets include industries and individuals.
Methodology HeartCrypt injects malicious code into legitimate executables. Techniques include:
➡ Control flow hijacking
➡ Obfuscation (stack strings, junk bytes, etc.)
➡ Anti-sandboxing methods (loop emulation and Windows Defender evasion)
Product Targeted Windows systems, particularly 32-bit binaries.
Malware Reference Associated with LummaStealer, Remcos RAT, XWorm, Quasar RAT, RedLine Stealer, and others.
Tools Used ➡ Telegram
➡ Underground forums (e.g., XSS.is, Exploit.in, BlackHatForums)
➡ API abuse (e.g., LoadResource, VirtualProtect)
Vulnerabilities Exploited Anti-sandbox evasion techniques targeting:
➡ Windows Defender’s VDLL
➡ VM detection with d3d9 library
➡ Dependency emulation checks
TTPs ➡ Packer services for malware
➡ Use of legitimate binaries for obfuscation
➡ Extensive use of control flow obfuscation (jmp instructions, PIC)
➡ Dynamic API resolution
➡ Tailored payload injection into binaries
Attribution Development observed since July 2023 by unknown operators, possibly cybercriminal syndicates.
Recommendations ➡ Implement robust sandboxing to detect obfuscated code
➡ Monitor suspicious use of LoadResource and other API calls
➡ Enhance behavioral analysis to detect unusual control flow manipulations
➡ Educate users about risks of downloading executables from unverified sources
Quelle  Palo Alto Networks (Unit 42)

Read full article: https://unit42.paloaltonetworks.com/packer-as-a-service-heartcrypt-malware/

The above summary has been generated by an AI language model

Quelle

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
1:29 am, Jan. 15, 2025
Wetter-Symbol 9°C
L: 8° | H: 9°
overcast clouds
Luftfeuchtigkeit: 92 %
Druck: 1034 mb
Wind: 8 mph WSW
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 100%
Regen Chance: 0%
Sichtbarkeit: 6 km
Sonnenaufgang: 7:59 am
Sonnenuntergang: 4:20 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 9:00 pm
Wetter-Symbol
8° | 9°°C 0 mm 0% 3 mph 97 % 1035 mb 0 mm/h
Tomorrow 9:00 pm
Wetter-Symbol
5° | 9°°C 0 mm 0% 4 mph 97 % 1034 mb 0 mm/h
Fr. Jan. 17 9:00 pm
Wetter-Symbol
3° | 7°°C 0 mm 0% 4 mph 91 % 1035 mb 0 mm/h
Sa. Jan. 18 9:00 pm
Wetter-Symbol
2° | 7°°C 0 mm 0% 4 mph 87 % 1034 mb 0 mm/h
So. Jan. 19 9:00 pm
Wetter-Symbol
2° | 6°°C 0 mm 0% 4 mph 88 % 1025 mb 0 mm/h
Today 3:00 am
Wetter-Symbol
6° | 8°°C 0 mm 0% 3 mph 94 % 1034 mb 0 mm/h
Today 6:00 am
Wetter-Symbol
6° | 7°°C 0 mm 0% 2 mph 96 % 1034 mb 0 mm/h
Today 9:00 am
Wetter-Symbol
6° | 6°°C 0 mm 0% 3 mph 97 % 1035 mb 0 mm/h
Today 12:00 pm
Wetter-Symbol
9° | 9°°C 0 mm 0% 2 mph 88 % 1035 mb 0 mm/h
Today 3:00 pm
Wetter-Symbol
9° | 9°°C 0 mm 0% 3 mph 88 % 1034 mb 0 mm/h
Today 6:00 pm
Wetter-Symbol
7° | 7°°C 0 mm 0% 3 mph 96 % 1034 mb 0 mm/h
Today 9:00 pm
Wetter-Symbol
6° | 6°°C 0 mm 0% 2 mph 97 % 1034 mb 0 mm/h
Tomorrow 12:00 am
Wetter-Symbol
6° | 6°°C 0 mm 0% 3 mph 96 % 1034 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€94,044.60
2.38%
Ethereum(ETH)
€3,126.85
2.49%
XRP(XRP)
€2.61
5.70%
Fesseln(USDT)
€0.97
-0.01%
Solana(SOL)
€181.89
2.44%
Dogecoin(DOGE)
€0.348878
4.93%
USDC(USDC)
€0.97
0.00%
Shiba Inu(SHIB)
€0.000021
2.19%
Pepe(PEPE)
€0.000016
2.61%
Peanut das Eichhörnchen(PNUT)
€0.60
4.05%
Nach oben scrollen