Malware.View on attack.mitre.org
HeartCrypt is a packer-as-a-service (PaaS) used to protect malware that has been available since at least 2024. HeartCrypt has been used to pack a variety of malware including Lumma Stealer, Remcos, and Rhadamanthys. In the HeartCrypt PaaS model, customers submit malware via private messaging services and it is then packed and returned by the operator as a new binary.
| Technique | Procedure example |
|---|---|
| T1027.001 Binary Padding |
HeartCrypt can add several hundred thousand kilobytes of null padding to payloads before saving onto the file system. |
| T1027.002 Software Packing |
HeartCrypt can pack malicious Windows x86 and .NET payloads in order to evade detection. |
| T1027.013 Encrypted/Encoded File |
HeartCrypt strings are encrypted via a single-byte XOR operation rotating over a hard-coded key, possibly provided by the PaaS customers. |
| T1036.008 Masquerade File Type |
HeartCrypt can append a BMP header to encoded malicious payloads to masquerade them as BMP files. |
| T1055.004 Asynchronous Procedure Call |
HeartCrypt has the ability to use `NtQueueApcThread` as an alternate method for process injection. |
| T1055.012 Process Hollowing |
For .NET payloads, HeartCrypt can use process hollowing to inject into processes spawned by csc.exe or AppLaunch.exe. |
| T1059.003 Windows Command Shell |
HeartCrypt can use the `reg add` command via `cmd.exe` for Registry modification. |
| T1106 Native API |
HeartCrypt can use Windows API functions to modify the Registry and `FindResourceW`, `LoadResource`, and `LockResource` to acquire a pointer to corresponding code resources. |
| T1140 Deobfuscate/Decode Files or Information |
HeartCrypt can decrypt payloads prior to execution. |
| T1497.001 System Checks |
HeartCrypt will attempt to load non-existent DLLs in attempt to detect sandbox creation of a dummy DLL to prevent the program from crashing. |
| T1547.001 Registry Run Keys / Startup Folder |
HeartCrypt can set the `CurrentVersion\Run` key to establish persistence. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.