Crypta

Description

(Kaspersky) Dropping Elephant introduced a new loader for BADNEWS, a tool we named Crypta. It contains mechanisms to hinder detection and appears to be a core component of this APT actor’s recent toolset. Crypta and its variants have been observed in multiple scenarios loading a wide range of subsequent payloads, such as Bozok, QuasarRAT and LokiBot.

Names

Name
Crypta

Category

Malware

Type

  • Loader

Information

Other Information

Uuid

93641ded-4ae6-488e-9c32-60aa9460fb22

Last Card Change

2021-05-16