Criminal services offering crypters are becoming more accessible. Researchers at Recorded Future identified a thriving market of sellers offering these services across underground forums, private communities, messaging platforms, websites, and social media. mrlapis (Source: Recorded Future) This makes the service more than just a simple file-scrambling tool; it also complicates the initial stages of an incident where analysts need to identify what actually ran.
o1oo1 (Source – Recorded Future) Detection Must Follow Behavior One prominent seller, mrlapis, has been advertising VIP Crypt for years, claiming continued evasion of Windows Defender, automatic re-encryption, and delivery through encrypted file transfer services.
Researchers recently discovered a new sample that employs a multi-stage Delphi loader, hidden resource data, staged decoding, and manual loading of a Windows executable directly into memory. ASMCrypt was observed producing HijackLoader packages that abuse legitimate signed programs and DLL sideloading before moving components into ProgramData and injecting code into another process. They should also investigate signed applications running from unexpected paths, side-loaded DLLs, encrypted configuration files, memory-only loading, and suspended processes that receive remote memory writes.
Careful analysis is crucial because public multi-scanner submissions can alert operators and trigger a newly encrypted version. Defenders must also treat password-protected archives, shortcut files, disk-image attachments, and document lookalikes as high-risk delivery methods, especially as SmartScreen bypass campaigns continue to exploit user trust.











