ATT&CKSoftwareHeartCrypt

HeartCrypt

S9018

Malware.View on attack.mitre.org

About this malware

HeartCrypt is a packer-as-a-service (PaaS) used to protect malware that has been available since at least 2024. HeartCrypt has been used to pack a variety of malware including Lumma Stealer, Remcos, and Rhadamanthys. In the HeartCrypt PaaS model, customers submit malware via private messaging services and it is then packed and returned by the operator as a new binary.

Techniques used11

Procedure examples11

TechniqueProcedure example
T1027.001
Binary Padding

HeartCrypt can add several hundred thousand kilobytes of null padding to payloads before saving onto the file system.

T1027.002
Software Packing

HeartCrypt can pack malicious Windows x86 and .NET payloads in order to evade detection.

T1027.013
Encrypted/Encoded File

HeartCrypt strings are encrypted via a single-byte XOR operation rotating over a hard-coded key, possibly provided by the PaaS customers.

T1036.008
Masquerade File Type

HeartCrypt can append a BMP header to encoded malicious payloads to masquerade them as BMP files.

T1055.004
Asynchronous Procedure Call

HeartCrypt has the ability to use `NtQueueApcThread` as an alternate method for process injection.

T1055.012
Process Hollowing

For .NET payloads, HeartCrypt can use process hollowing to inject into processes spawned by csc.exe or AppLaunch.exe.

T1059.003
Windows Command Shell

HeartCrypt can use the `reg add` command via `cmd.exe` for Registry modification.

T1106
Native API

HeartCrypt can use Windows API functions to modify the Registry and `FindResourceW`, `LoadResource`, and `LockResource` to acquire a pointer to corresponding code resources.

T1140
Deobfuscate/Decode Files or Information

HeartCrypt can decrypt payloads prior to execution.

T1497.001
System Checks

HeartCrypt will attempt to load non-existent DLLs in attempt to detect sandbox creation of a dummy DLL to prevent the program from crashing.

T1547.001
Registry Run Keys / Startup Folder

HeartCrypt can set the `CurrentVersion\Run` key to establish persistence.

Groups that use it1

Campaigns0

None recorded.

References1

  1. Palo Alto HeartCrypt DEC 2024 Open source
    Tujague, J., Bunce, D. (n.d.). Crypted Hearts: Exposing the HeartCrypt Packer-as-a-Service Operation. Retrieved April 16, 2026.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.