HeartCrypt
MITRE ATT&CK: S9018 View on attack.mitre.org
Aliases: HeartCrypt
- Family
- Malware family
- Operating systems
- linux, windows
- Profile updated
- 2026-07-07 15:30:33
Context
HeartCrypt is a packer-as-a-service (PaaS) used to protect malware that has been available since at least 2024. HeartCrypt has been used to pack a variety of malware including Lumma Stealer, Remcos, and Rhadamanthys. In the HeartCrypt PaaS model, customers submit malware via private messaging services and it is then packed and returned by the operator as a new binary.
Detection coverage
- 94 Sigma rules
Malware & tools used
- Asynchronous Procedure Call (attack-pattern)
- Masquerade File Type (attack-pattern)
- Process Hollowing (attack-pattern)
- System Checks (attack-pattern)
- Deobfuscate/Decode Files or Information (attack-pattern)
- Software Packing (attack-pattern)
- Encrypted/Encoded File (attack-pattern)
- Registry Run Keys / Startup Folder (attack-pattern)
- Windows Command Shell (attack-pattern)
- Native API (attack-pattern)
- Binary Padding (attack-pattern)
Used by threat actors
- APT-C-36 (threat-actor)
Reports & references
- MITRE ATT&CK — S9018 (report)
- Palo Alto Unit 42 — Packer As A Service Heartcrypt Malware (report)