CrackedCantil
- Malware type
- dropper, loader, cryptominer, ransomware
- Profile updated
- 2026-07-07 14:44:28
Targeted industries: technology-and-telecommunications financial-services
Context
According to ANY.RUN, this is a dropper for win.privateloader and its execution will lead to a cascade of downloads with a large variety of additional malware. The families include more loaders, information stealers, cryptominers, a proxy bot, and ultimately also ransomware. The execution order is orchestrated, e.g. as in data is stolen and exfiltrated before encryption. It is distributed through advertized cracked software, e.g. IDA Pro.
Detection coverage
- 1 YARA rules
Detection rules
- MALPEDIA_Win_Crackedcantil_Auto (yara-rule)
Reports & references
- any.run — Crackedcantil Breakdown (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Crackedcantil (report)
- thehackernews.com — Beware Fake Facebook Job Ads Spreading (report)
- pcrisk.com — 28989 Crackedcantil Malware (report)
- infostealers.com — Crackedcantil A Malware Symphony Breakdown (report)
- virusbulletin.com — Crackedcantil A Malware Symphony Delivered By Cracked Software Performed By Loaders Infostealers Ransomware Et Al (report)
- g0njxa.medium.com — Privateloader Installskey Rewind 2023 C1Ce027Cbe65 (report)
- xfe-integration.xforce.ibm.com — Guid:F8F1276C350A70B7B543990E4Fb53A76 (report)
- cloudsek.com — From Discussion Forums To Malware Mayhem The Alarming Rise Of Abuse On Google Groups And Usenet (report)
- otx.alienvault.com — 65Ba54Eeaea0Fcd931Ff3B3B (report)
- gridinsoft.com — Crackedcantil Dropper Malware (report)