Brian Sims
Editor

Malware crypting services “aim to preserve payloads after exposure”

THE LATEST report issued by Recorded Future’s Insikt Group identifies a competitive market on The Dark Web and underground forums involving cyber criminals selling malware crypting services, which are designed to help adversaries bypass detection and preserve malware usability after exposure.

The document highlights that services from threat actors have grown well beyond basic file encryption and could make it increasingly difficult for security teams to keep up if they focus too heavily on what a crypted file looks like.

The malware crypting services of 24 threat actors were analysed within the past year, with findings showing a heavy focus on Windows payloads. Advertised services and products offered combine payload wrapping, in-memory execution, anti-analysis checks, process injection, persistence options, delivery packaging and post-detection ‘cleaning’ or re-crypting services.

Reducing detection 

Alexander Leslie, senior advisor at Recorded Future, commented: “Advertised malware crypter capabilities vary by provider, but tend to focus on reducing detection, delaying or preventing analysis and supporting stealthier payload execution.”

Leslie continued: “More established providers of such services are staying involved after the sale as they continue to adjust their payloads in response to security products recognising them. This gives their customers a way in which to keep using the same malware for longer, meaning that defenders should prioritise behaviour detection over static indicators.”

Findings from the analysis show that cyber criminals are advertising crypter capabilities through underground forums, restricted communities, chat platforms, clearnet sites and social media accounts. They compete through tiered pricing, anti-virus detection scores of crypted samples, discounts, malware-developer partnerships, private or shared stubs and promised turnaround times for re-crypting detected payloads.

Popular crypting service providers primarily advertise support for Windows payloads, with no advertising identified for macOS or Linux crypting services.

Concentration of effort

Alexander Leslie stated: “Windows is where almost all of the providers we reviewed are concentrating their effort, reflecting the size of the customer base and the maturity of the malware ecosystem around it. However, this shouldn’t be taken to mean Windows is inherently easier to compromise.”

Further, Leslie noted: “A crypter can give malware a better chance of running before security tools catch it. What happens after that still depends on the payload and the person operating it. For defenders, the problem is that the opportunity to see the malware and respond may be shorter.”

In addition, Leslie observed: “Security teams will struggle to keep up if they focus too heavily on what a crypted file looks like. The file can change quickly when the provider reworks it, but the way in which it behaves during execution tends to be more consistent. This gives defenders something more durable to detect. The priority focus should be on how crypted payloads execute rather than how individual crypted files appear.”

Concluding the commentary on this issue, Leslie said: “Anti-virus and endpoint detection and response tools should not be treated as sufficient protection against crypted payloads. Defenders should pair endpoint controls with behaviour-based detection, telemetry correlation, upstream hunting, suspicious process monitoring and rapid triage of suspicious samples.”

*Further information is available online at www.recordedfuture.com

Company Info

Western Business Media Limited

Dorset House
64 High Street
East Grinstead
RH19 3DE
UNITED KINGDOM

Login / Sign up