HeartCrypt — Malware Profile
HeartCrypt is a packer-as-a-service (PaaS) used to protect malware that has been available since at least 2024. HeartCrypt has been used to pack a variety of malware including Lumma Stealer, Remcos, and Rhadamanthys. In the HeartCrypt PaaS model, customers submit malware via private messaging services and it is then packed and returned by the operator as a new binary.
MITRE ATT&CK techniques (11)
- T1027.001 Binary Padding
- T1027.002 Software Packing
- T1027.013 Encrypted/Encoded File
- T1036.008 Masquerade File Type
- T1055.004 Asynchronous Procedure Call
- T1055.012 Process Hollowing
- T1059.003 Windows Command Shell
- T1106 Native API
- T1140 Deobfuscate/Decode Files or Information
- T1497.001 System Checks
- T1547.001 Registry Run Keys / Startup Folder