CrackedCantil

Malware type
dropper, loader, cryptominer, ransomware
Profile updated
2026-07-07 14:44:28

Targeted industries: technology-and-telecommunications financial-services

Context

According to ANY.RUN, this is a dropper for win.privateloader and its execution will lead to a cascade of downloads with a large variety of additional malware. The families include more loaders, information stealers, cryptominers, a proxy bot, and ultimately also ransomware. The execution order is orchestrated, e.g. as in data is stolen and exfiltrated before encryption. It is distributed through advertized cracked software, e.g. IDA Pro.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Crackedcantil_Auto (yara-rule)

Reports & references

  • any.run — Crackedcantil Breakdown (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Crackedcantil (report)
  • thehackernews.com — Beware Fake Facebook Job Ads Spreading (report)
  • pcrisk.com — 28989 Crackedcantil Malware (report)
  • infostealers.com — Crackedcantil A Malware Symphony Breakdown (report)
  • virusbulletin.com — Crackedcantil A Malware Symphony Delivered By Cracked Software Performed By Loaders Infostealers Ransomware Et Al (report)
  • g0njxa.medium.com — Privateloader Installskey Rewind 2023 C1Ce027Cbe65 (report)
  • xfe-integration.xforce.ibm.com — Guid:F8F1276C350A70B7B543990E4Fb53A76 (report)
  • cloudsek.com — From Discussion Forums To Malware Mayhem The Alarming Rise Of Abuse On Google Groups And Usenet (report)
  • otx.alienvault.com — 65Ba54Eeaea0Fcd931Ff3B3B (report)
  • gridinsoft.com — Crackedcantil Dropper Malware (report)

External references