Cyber Security News

Malware Crypter Services Sell Windows Defender, EDR and SmartScreen Bypasses to Cybercriminals

Criminal services that hide malware are becoming easier to buy. These services, known as crypters, change a malicious file so that security tools struggle to recognize it.

Their operators promise customers a way around Windows Defender, endpoint detection and response tools, and Microsoft SmartScreen. The change helps attackers move familiar malware past controls that would otherwise flag it early.

The danger is not a single new malware family. It is a commercial layer that helps many kinds of malware reach victims with less scrutiny.

Criminals can package remote access tools, stealers, or ransomware loaders into files designed to look different each time they are delivered.

Recorded Future said in a report shared with Cyber Security News (CSN) that a successful bypass can give an intrusion time to establish itself before defenders know a harmful program is present.

Analysts at Recorded Future identified a busy market of sellers offering these services across underground forums, private communities, messaging platforms, websites, and social media.

The researchers reviewed 24 active providers and found that Windows payloads remain the main focus, while Android support also appears in the market.

Their findings show how a specialist criminal service can support many separate campaigns.

Malware Crypter Services Sell Windows Defender, EDR and SmartScreen Bypasses

A crypter starts with a customer-supplied malicious program and encrypts or disguises it.

More capable offerings go further, adding memory-only execution, checks for virtual machines and sandboxes, process injection, persistence, and fresh versions after a file is detected.

mrlapis (Source – Recorded Future)

That makes the service a delivery framework, not merely a file-scrambling tool. It also complicates the first minutes of an incident, when analysts need to identify what actually ran.

The sellers advertise “fully undetectable” results and use subscription plans, private or shared software wrappers, and promised cleaning times to compete.

Their claims should be treated cautiously, but the business model matters: it puts established evasion methods in reach of criminals who do not have the skill to build them.

A recent Windows security warning bypass shows why download-origin protections remain an important layer, even when attackers seek ways around them.

o1oo1 (Source – Recorded Future)

Recorded Future said in a report shared with Cyber Security News that advanced providers advertise Windows Defender and SmartScreen bypasses, antivirus-killing functions, AMSI bypasses, Event Tracing for Windows patching, and direct system calls.

Providers also promote DLL injection, process hollowing, and other methods intended to conceal the final payload while it runs.

Detection Must Follow Behavior

One prominent seller, mrlapis, has advertised VIP Crypt for years and claims continuing Windows Defender evasion, automatic re-encryption, and delivery through encrypted file transfer services.

Researchers found a recent sample used a multi-stage Delphi loader, hidden resource data, staged decoding, and manual loading of a Windows executable directly into memory.

That approach weakens reliance on simple file signatures or hashes. Other services extend the deception.

ASMCrypt was observed producing HijackLoader packages that abuse legitimate signed programs and DLL sideloading before moving components into ProgramData and injecting code into another process.

Security teams have seen related risks when attackers disable EDR agents or use stolen code-signing certificates to make malicious files appear trustworthy.

Organizations should look for actions that crypted files cannot easily hide: unexpected security-product discovery or tampering, suspicious Defender exclusions, and unsigned files launched from temporary, download, archive, or user-writable folders.

ImComplexed (Source – Recorded Future)

They should also investigate signed applications running from unusual paths, side-loaded DLLs, encrypted configuration files, memory-only loading, and suspended processes that receive remote memory writes.

Restricting execution from user-writable and archive-extraction paths, enabling tamper protection, and isolating systems with suspected crypted malware can limit damage.

Teams should retain the original file, staged components, memory evidence, and process telemetry, then determine the final payload and any follow-on activity.

Careful analysis matters because public multi-scanner submissions can warn operators and trigger a newly crypted version.

Defenders should also treat password-protected archives, shortcut files, disk-image attachments, and document lookalikes as higher-risk delivery methods, particularly as SmartScreen bypass campaigns continue to exploit user trust.

These controls cannot stop every intrusion, but they reduce the opportunities for a disguised payload to run unnoticed.

Indicators of comrpomise (IoCs):-

TypeIndicatorDescription
Telegram handle@mrlapis_realContact handle associated with mrlapis and the VIP Crypt service
Tox ID2912CA4F42B6B37C749D759C43340959D5B9DE74E0242B83A3C5CF27FDADAA1DF83038A66255Tox contact identifier associated with mrlapis
Jabber addressmrlapis@exploit[.]imJabber contact associated with mrlapis
IP address46[.]183[.]217[.]105Address associated with mrlapis
FTPS endpoint91[.]92[.]242[.]14[:]9090FTPS server reportedly used by mrlapis for crypted-file delivery
FTPS endpoint5[.]61[.]36[.]246[:]9090Additional FTPS endpoint previously observed distributing crypted content
DomainTemp[.]shTemporary file-upload service used in the VIP Crypt purchase workflow
Domainavcheck[.]netMulti-antivirus scanning service referenced in VIPCrypt testing claims
Domainscanner[.]toMulti-antivirus scanning service referenced in VIPCrypt testing claims

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Stop new phishing & malware before they compromise your business. Integrate live intel from 15K SOCs around the world

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Recent Posts

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

4 hours ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

14 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

15 hours ago

Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices

Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…

15 hours ago

How to Keep Malware’s Rotating Infrastructure From Becoming a Detection Gap

You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…

15 hours ago

Microsoft Bans Its AI Models From Launching Cyberattacks or Escalating Their Own Access

Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…

15 hours ago