Tujague, J., Bunce, D. (n.d.). Crypted Hearts: Exposing the HeartCrypt Packer-as-a-Service Operation. Retrieved April 16, 2026.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.001 Binary Padding |
MalwareHeartCrypt | HeartCrypt can add several hundred thousand kilobytes of null padding to payloads before saving onto the file system. |
| T1027.002 Software Packing |
MalwareHeartCrypt | HeartCrypt can pack malicious Windows x86 and .NET payloads in order to evade detection. |
| T1027.013 Encrypted/Encoded File |
MalwareHeartCrypt | HeartCrypt strings are encrypted via a single-byte XOR operation rotating over a hard-coded key, possibly provided by the PaaS customers. |
| T1036.008 Masquerade File Type |
MalwareHeartCrypt | HeartCrypt can append a BMP header to encoded malicious payloads to masquerade them as BMP files. |
| T1055.004 Asynchronous Procedure Call |
MalwareHeartCrypt | HeartCrypt has the ability to use `NtQueueApcThread` as an alternate method for process injection. |
| T1055.012 Process Hollowing |
MalwareHeartCrypt | For .NET payloads, HeartCrypt can use process hollowing to inject into processes spawned by csc.exe or AppLaunch.exe. |
| T1059.003 Windows Command Shell |
MalwareHeartCrypt | HeartCrypt can use the `reg add` command via `cmd.exe` for Registry modification. |
| T1106 Native API |
MalwareHeartCrypt | HeartCrypt can use Windows API functions to modify the Registry and `FindResourceW`, `LoadResource`, and `LockResource` to acquire a pointer to corresponding code resources. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareHeartCrypt | HeartCrypt can decrypt payloads prior to execution. |
| T1497.001 System Checks |
MalwareHeartCrypt | HeartCrypt will attempt to load non-existent DLLs in attempt to detect sandbox creation of a dummy DLL to prevent the program from crashing. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareHeartCrypt | HeartCrypt can set the `CurrentVersion\Run` key to establish persistence. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.