cognitive cybersecurity intelligence

News and Analysis

Search

Malware Crypter Services Sell Windows Defender, EDR and SmartScreen Bypasses to Cybercriminals

Malware Crypter Services Sell Windows Defender, EDR and SmartScreen Bypasses to Cybercriminals

Criminal services that hide malware are becoming easier to buy. These services, known as crypters, change a malicious file so that security tools struggle to recognize it.

Their operators promise customers a way around Windows Defender, endpoint detection and response tools, and Microsoft SmartScreen. The change helps attackers move familiar malware past controls that would otherwise flag it early.

The danger is not a single new malware family. It is a commercial layer that helps many kinds of malware reach victims with less scrutiny.

Criminals can package remote access tools, stealers, or ransomware loaders into files designed to look different each time they are delivered.

Recorded Future said in a report shared with Cyber Security News (CSN) that a successful bypass can give an intrusion time to establish itself before defenders know a harmful program is present.

Analysts at Recorded Future identified a busy market of sellers offering these services across underground forums, private communities, messaging platforms, websites, and social media.

The researchers reviewed 24 active providers and found that Windows payloads remain the main focus, while Android support also appears in the market.

Their findings show how a specialist criminal service can support many separate campaigns.

Malware Crypter Services Sell Windows Defender, EDR and SmartScreen Bypasses

A crypter starts with a customer-supplied malicious program and encrypts or disguises it.

More capable offerings go further, adding memory-only execution, checks for virtual machines and sandboxes, process injection, persistence, and fresh versions after a file is detected.

mrlapis (Source – Recorded Future)

That makes the service a delivery framework, not merely a file-scrambling tool. It also complicates the first minutes of an incident, when analysts need to identify what actually ran.

The sellers advertise “fully undetectable” results and use subscription plans, private or shared software wrappers, and promised cleaning times to compete.

Their claims should be treated cautiously, but the business model matters: it puts established evasion methods in reach of criminals who do not have the skill to build them.

A recent Windows security warning bypass shows why download-origin protections remain an important layer, even when attackers seek ways around them.

o1oo1 (Source – Recorded Future)

Recorded Future said in a report shared with Cyber Security News that advanced providers advertise Windows Defender and SmartScreen bypasses, antivirus-killing functions, AMSI bypasses, Event Tracing for Windows patching, and direct system calls.

Providers also promote DLL injection, process hollowing, and other methods intended to conceal the final payload while it runs.

Detection Must Follow Behavior

One prominent seller, mrlapis, has advertised VIP Crypt for years and claims continuing Windows Defender evasion, automatic re-encryption, and delivery through encrypted file transfer services.

Researchers found a recent sample used a multi-stage Delphi loader, hidden resource data, staged decoding, and manual loading of a Windows executable directly into memory.

That approach weakens reliance on simple file signatures or hashes. Other services extend the deception.

ASMCrypt was observed producing HijackLoader packages that abuse legitimate signed programs and DLL sideloading before moving components into ProgramData and injecting code into another process.

Security teams have seen related risks when attackers disable EDR agents or use stolen code-signing certificates to make malicious files appear trustworthy.

Organizations should look for actions that crypted files cannot easily hide: unexpected security-product discovery or tampering, suspicious Defender exclusions, and unsigned files launched from temporary, download, archive, or user-writable folders.

ImComplexed (Source – Recorded Future)

They should also investigate signed applications running from unusual paths, side-loaded DLLs, encrypted configuration files, memory-only loading, and suspended processes that receive remote memory writes.

Restricting execution from user-writable and archive-extraction paths, enabling tamper protection, and isolating systems with suspected crypted malware can limit damage.

Teams should retain the original file, staged components, memory evidence, and process telemetry, then determine the final payload and any follow-on activity.

Careful analysis matters because public multi-scanner submissions can warn operators and trigger a newly crypted version.

Defenders should also treat password-protected archives, shortcut files, disk-image attachments, and document lookalikes as higher-risk delivery methods, particularly as SmartScreen bypass campaigns continue to exploit user trust.

These controls cannot stop every intrusion, but they reduce the opportunities for a disguised payload to run unnoticed.

Indicators of comrpomise (IoCs):-

TypeIndicatorDescriptionTelegram handle@mrlapis_realContact handle associated with mrlapis and the VIP Crypt serviceTox ID2912CA4F42B6B37C749D759C43340959D5B9DE74E0242B83A3C5CF27FDADAA1DF83038A66255Tox contact identifier associated with mrlapisJabber addressmrlapis@exploit[.]imJabber contact associated with mrlapisIP address46[.]183[.]217[.]105Address associated with mrlapisFTPS endpoint91[.]92[.]242[.]14[:]9090FTPS server reportedly used by mrlapis for crypted-file deliveryFTPS endpoint5[.]61[.]36[.]246[:]9090Additional FTPS endpoint previously observed distributing crypted contentDomainTemp[.]shTemporary file-upload service used in the VIP Crypt purchase workflowDomainavcheck[.]netMulti-antivirus scanning service referenced in VIPCrypt testing claimsDomainscanner[.]toMulti-antivirus scanning service referenced in VIPCrypt testing claims

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Stop new phishing & malware before they compromise your business. Integrate live intel from 15K SOCs around the world
The post Malware Crypter Services Sell Windows Defender, EDR and SmartScreen Bypasses to Cybercriminals appeared first on Cyber Security News.

Source: cybersecuritynews.com –

Subscribe to newsletter

Subscribe to HEAL Security Dispatch for the latest healthcare cybersecurity news and analysis.

More Posts