Skip to content

Executive Summary

The CryptBot has undergone significant evolution over two years, moving from an initial version compiled with msvc and using XOR encryption to a modern iteration utilizing minGw, heavy obfuscation, and RC4 for configuration protection. The history details Version 1, which used XOR encryption and was packed, referencing specific file hashes and C2 addresses. Version 2 introduced RC4 encryption and was unpacked, including an embedded PowerShell command to deploy the NetSupport Client as a backdoor. Version 3.1 features dynamic RC4 encryption and includes embeddable clipboard crypto stealer capabilities. Both versions reference similar C2 infrastructure, including domains like `ovapfa05.top` and `tventyvx20pn.top`, and use specific file names and system information collection methods for data exfiltration.

Facts Only

Version 1 used msvc compilation and XOR encryption; hash: 7ccda59528c0151bc9f11b7f25f8291d99bcf541488c009ef14e2a104e6f0c5d.
Version 2 used msvc compilation and RC4 encryption; hash: 34dcc780d2a2357c52019d87a0720802a92f358d15320247c80cc21060fb6f57.
Version 1 and Version 2 included C2 addresses: http://erniku42.top/gate.php and http://ovapfa05.top/unfele.dat
Version 2 involved a PowerShell command to deploy the NetSupport Client.
Version 3.1 involves dynamic RC4 encryption and an embedded clipboard crypto stealer.
The process involves collecting system information including CPU, RAM, GPU, and user data.
File operations documented include accessing paths like \ServiceData\Clip.jpg and executing `schtasks` commands.
The malware utilizes various standard Windows API calls (e.g., CreateProcess, VirtualAlloc) and networking functions (e.g., WinHttpSendRequest).
The C2 infrastructure involves endpoints such as `gceight8vt.top`, `analforeverlovyu.top`, and `tventyvx20pn.top`.

Full Take

The evolution of the CryptBot demonstrates a clear pattern of iterative operational hardening designed to evade detection while maintaining core functionality, moving from simple XOR protection to complex RC4 obfuscation. This progression suggests an ongoing adversarial relationship where defenders must constantly re-evaluate static indicators against dynamic changes in malware construction. The shift involves not just cryptographic implementation but also shifting the method of persistence and exfiltration, evidenced by the transition from simple configuration files to embedding secondary payloads like the NetSupport Client.
The reuse of specific, seemingly randomized identifiers across multiple versions—such as unique file hashes, C2 domains, and internal artifacts like "Anal" build files—suggests a coordinated operational structure rather than disparate development efforts. This points toward a centralized command or lineage guiding these iterations, where each release functions as an updated layer within a larger persistence strategy. The underlying mechanism consistently focuses on deep system enumeration and payload delivery, indicating the primary objective is sustained access and data extraction regardless of superficial obfuscation techniques employed.
The implications suggest that static analysis based on old indicators will be insufficient for tracking this threat; resilience requires monitoring behavioral shifts rather than relying solely on signature matching. The constant refinement points to an adaptive adversary whose success relies on exploiting the gap between the complexity of the disguise and the simplicity of the underlying malicious goal. What systems are in place to monitor for deviations in system calls or network behavior that might correlate with these observed file operations? How does tracking the shared artifact hashes inform the understanding of the threat's long-term operational life?

From the original · OALABS

Tracking the many iterations of this stealer Overview CryptBot has evolved significantly over the past two years. Starting out as a simple stealer compiled with msvc and and containing an XOR encrypted config, the developers have released multiple iterations of the bot attempting to distence themselves from the orignal stealer.
Read the full story at research.openanalysis.net