HeartCrypt

MITRE ATT&CK: S9018 View on attack.mitre.org

Aliases: HeartCrypt

Family
Malware family
Operating systems
linux, windows
Profile updated
2026-07-07 15:30:33

Context

HeartCrypt is a packer-as-a-service (PaaS) used to protect malware that has been available since at least 2024. HeartCrypt has been used to pack a variety of malware including Lumma Stealer, Remcos, and Rhadamanthys. In the HeartCrypt PaaS model, customers submit malware via private messaging services and it is then packed and returned by the operator as a new binary.

Detection coverage

  • 94 Sigma rules

Malware & tools used

  • Asynchronous Procedure Call (attack-pattern)
  • Masquerade File Type (attack-pattern)
  • Process Hollowing (attack-pattern)
  • System Checks (attack-pattern)
  • Deobfuscate/Decode Files or Information (attack-pattern)
  • Software Packing (attack-pattern)
  • Encrypted/Encoded File (attack-pattern)
  • Registry Run Keys / Startup Folder (attack-pattern)
  • Windows Command Shell (attack-pattern)
  • Native API (attack-pattern)
  • Binary Padding (attack-pattern)

Used by threat actors

Reports & references

  • MITRE ATT&CK — S9018 (report)
  • Palo Alto Unit 42 — Packer As A Service Heartcrypt Malware (report)

External references