Underground sellers make antivirus evasion a paid service

Antivirus and endpoint detection tools are what most organizations ultimately rely on to stop malware, and there is a competitive criminal market whose entire product is getting past them. Recorded Future's Insikt Group profiled 24 threat actors selling that service over the past year and describes a trade that behaves like any other software business: tiered pricing, reputation scores, partnerships and after-sales support.

The service is called crypting. At its simplest it means encrypting or obfuscating a customer's malicious file so security products no longer recognize it. Mature providers now sell a good deal more than that, bundling in-memory execution, anti-analysis checks, process injection, persistence, delivery packaging, and a "cleaning" or re-crypting service that refreshes a payload once defenders start catching it.

What is actually being sold

Insikt Group's review of the advertisements found crypters that check whether they are running in a virtual machine, a sandbox or under a debugger before executing, and that call the Windows Sleep function to stall long enough for automated analysis to give up. Sellers advertise Windows Defender and SmartScreen bypasses, AMSI bypass, Event Tracing for Windows patching, syscall unhooking and antivirus kill functionality, plus process injection methods including DLL injection, process hollowing, APC injection and reflective .NET assembly loading. Persistence is an optional extra, chosen from a menu running from registry Run keys and scheduled tasks to WMI event subscriptions, COM hijacking and Winlogon shell modification.

Microsoft's controls are the most commonly named evasion target, with Kaspersky, ESET, Bitdefender, Norton, Avast, AVG, Malwarebytes, Trend Micro, CrowdStrike, SentinelOne and Carbon Black also called out by name in the ads. Insikt Group is careful to say those are provider-advertised capabilities unless corroborated through sample analysis, detection telemetry or third-party reporting.

A reputation market

Providers advertise on underground forums, restricted communities, chat platforms such as Telegram and Tox, clearnet sites they run themselves, and even social media accounts. They compete on the antivirus detection scores of crypted samples, turnaround time for re-crypting a burned payload, private versus shared stubs, and partnerships with malware developers. To back a claim that a build is "fully undetectable", sellers scan it through multi-engine services, most often KleenScan, which does not store and expose samples to researchers the way public sandboxes do.

One long-running example the report names is "mrlapis", active since at least 2011 and selling a service called VIP Crypt on a subscription of $500 a week, with files re-encrypted every ten minutes and delivered over FTPS. Insikt Group associates the actor with the IP address 46[.]183[.]217[.]105, an Air VPN exit node in Latvia, and has observed crypted payloads delivered from FTPS servers at 91[.]92[.]242[.]14 and 5[.]61[.]36[.]246. A separate provider, "GoldenCrypt", is reportedly affiliated with several malware families, an arrangement Insikt Group reads as being as much a marketing tactic as a technical one. The link to real intrusions is documented: in July 2025 eSentire reported an association between PureRAT and the GhostCrypt crypting service in an attack that impacted a US accounting firm in May 2025.

What defenders should take from it

Insikt Group's central recommendation is blunt. Antivirus and EDR should not be treated as sufficient standalone protection against crypted payloads, and defenders should prioritize behavioral detection over static indicators, paired with telemetry correlation, upstream hunting, suspicious process monitoring and rapid triage of suspicious samples. The analysts also draw a boundary around the threat: crypted payloads make execution more likely and detection slower, but they do not independently provide end-to-end intrusion capability, since lateral movement, data theft and ransomware deployment still depend on the malware inside. Every provider reviewed advertised support for Windows payloads and none advertised macOS or Linux crypting, which the report is explicit does not make Windows inherently more susceptible. It is the same commoditization visible in builder-made remote access trojans sold on to unrelated crews and in loader chains that run entirely in memory to stay off disk. The full analysis, including all 24 actors, is in the original report from Recorded Future's Insikt Group.

This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Read the full analysis on IntelFusions