ATT&CKReferencesPalo Alto HeartCrypt DEC 2024

Palo Alto HeartCrypt DEC 2024

Tujague, J., Bunce, D. (n.d.). Crypted Hearts: Exposing the HeartCrypt Packer-as-a-Service Operation. Retrieved April 16, 2026.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples11

TechniqueUsed byProcedure example
T1027.001
Binary Padding
MalwareHeartCrypt

HeartCrypt can add several hundred thousand kilobytes of null padding to payloads before saving onto the file system.

T1027.002
Software Packing
MalwareHeartCrypt

HeartCrypt can pack malicious Windows x86 and .NET payloads in order to evade detection.

T1027.013
Encrypted/Encoded File
MalwareHeartCrypt

HeartCrypt strings are encrypted via a single-byte XOR operation rotating over a hard-coded key, possibly provided by the PaaS customers.

T1036.008
Masquerade File Type
MalwareHeartCrypt

HeartCrypt can append a BMP header to encoded malicious payloads to masquerade them as BMP files.

T1055.004
Asynchronous Procedure Call
MalwareHeartCrypt

HeartCrypt has the ability to use `NtQueueApcThread` as an alternate method for process injection.

T1055.012
Process Hollowing
MalwareHeartCrypt

For .NET payloads, HeartCrypt can use process hollowing to inject into processes spawned by csc.exe or AppLaunch.exe.

T1059.003
Windows Command Shell
MalwareHeartCrypt

HeartCrypt can use the `reg add` command via `cmd.exe` for Registry modification.

T1106
Native API
MalwareHeartCrypt

HeartCrypt can use Windows API functions to modify the Registry and `FindResourceW`, `LoadResource`, and `LockResource` to acquire a pointer to corresponding code resources.

T1140
Deobfuscate/Decode Files or Information
MalwareHeartCrypt

HeartCrypt can decrypt payloads prior to execution.

T1497.001
System Checks
MalwareHeartCrypt

HeartCrypt will attempt to load non-existent DLLs in attempt to detect sandbox creation of a dummy DLL to prevent the program from crashing.

T1547.001
Registry Run Keys / Startup Folder
MalwareHeartCrypt

HeartCrypt can set the `CurrentVersion\Run` key to establish persistence.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.