HeartCrypt, a new packer-as-a-service (PaaS) tool developed in 2023 and launched in 2024, has quickly become a potent tool for malware operators. It helps evade antivirus detection by injecting malicious code into legitimate executable files, making detection difficult. Primarily used by malware operators using LummaStealer, Remcos, and Rhadamanthys, HeartCrypt charges $20 per file for packing Windows x86 and .NET payloads. It also integrates anti-sandbox and anti-emulation techniques escalating cybersecurity challenges.
NodeLoader Exposed: The Node.js Malware Evading Detection
Zscaler ThreatLabz has uncovered a malware campaign dubbed NodeLoader, which employs Node.js applications to deliver harmful payloads such as cryptocurrency miners and information stealers. Exploiting