VIP Crypt and ASMCrypt: Commercial Crypter Services Enabling Malware Evasion of Windows Defenses

VIP Crypt and ASMCrypt (TL-2026-2014), also tracked as VIP Crypt, is a medium-severity malware campaign, first published 2026-08-14. It is attributed to TOP RAT with high confidence, affects Microsoft Windows (Defender/SmartScreen and third-party AV/EDR on, maps to 16 MITRE ATT&CK techniques (T1027.002, T1027.009, T1036.005), and is covered by 9 detection rules and 19 indicators of compromise.

Key facts for TL-2026-2014

Threat ID
TL-2026-2014
Also known as
VIP Crypt, ASMCrypt, TOP RAT, SnappyClient, Private Protector
Severity
MEDIUM
Status
ACTIVE
Category
MALWARE
First published
2026-08-14
Last reviewed
2026-08-14
Attribution
TOP RAT
Attribution confidence
HIGH
Motivation
FINANCIAL
Detection rules
9
Indicators of compromise
19

Malware and tooling in VIP Crypt and ASMCrypt

Malware and tooling: HijackLoader, SnappyClient, telegram, ASMCrypt, Private Protector, TOP RAT / SnappyClient, VIP Crypt

Recorded Future's Insikt Group profiled 24 active malware-crypting-service providers, including VIP Crypt (operator mrlapis, $500/week) and ASMCrypt (operator o1oo1, $3,000/month, bundled with the TOP RAT/SnappyClient for $7,000/month), which sell multi-stage Delphi loaders, AMSI/ETW bypasses, direct syscalls, manual PE mapping, and anti-VM/anti-debug checks to help commodity stealers, RATs, and ransomware loaders such as HijackLoader evade Windows Defender and EDR.

How VIP Crypt and ASMCrypt works

Crypting-as-a-service has matured from simple binary obfuscation into full 'malware-enablement services' combining payload encryption, anti-analysis tooling, process injection, and persistence support behind subscription storefronts on forums such as Exploit, Telegram, Tox, and Jabber. Recorded Future's Insikt Group analyzed 24 such providers active over the past year; this threat tracks the report's two flagship offerings plus closely related actors it names.

mrlapis has operated VIP Crypt since 2011 (~$83,000 in estimated proceeds), selling a $500/week subscription that wraps 64-bit .exe/.dll payloads in a multi-stage Delphi loader: hidden resource-based storage, AES-256 encryption with in-memory decryption, manual PE mapping that bypasses the standard Windows loader, and runtime re-encryption of the stub roughly every 10 minutes to defeat static signatures. The service is fronted by a Telegram handle (@mrlapis_real), a Tox ID, and a Jabber address on exploit.im, with an AirVPN (Latvia) egress IP and two FTPS delivery servers used to hand off encrypted builds to customers.

o1oo1 has run ASMCrypt (and the bundled TOP RAT/SnappyClient) for roughly five years, generating an estimated $3.6 million; ASMCrypt is priced at $3,000/month standalone or $7,000/month bundled with the RAT. It targets polymorphic .NET (x86/x64) payloads, offers customizable anti-VM checks (RAM size, CPU model, hypervisor artifacts, MAC address, GPU name), and can add Windows Defender exclusions without invoking PowerShell. Its headline feature is integration with HijackLoader, a modular loader independently documented (by CrowdStrike and others) using interactive process hollowing of a pipe-fed cmd.exe, a transacted-section 'process doppelgänging' write into a spawned logagent.exe, and standard DLL hollowing of the legitimate mshtml.dll. HijackLoader implements Heaven's Gate (x86-to-x64 mode switching) to remap ntdll and issue direct/indirect syscalls — NtCreateSection, NtMapViewOfSection, NtWriteVirtualMemory, NtProtectVirtualMemory, NtResumeThread, and related APIs — bypassing user-mode EDR hooks, and decodes its configuration via XOR followed by LZNT1 (RtlDecompressBuffer) decompression. HijackLoader has been used across the industry to deliver Cobalt Strike beacons, LummaC2, RedLine Stealer, Danabot, and SystemBC, among other stealer/RAT payloads.

Insikt Group's broader market snapshot names related actors relevant to this same crypting-service ecosystem: ImComplexed's Private Protector (active since July 2020, tiers from $1,000 one-time to $12,000-$20,000/month, x64/x86/ARM support), separately reported by Intel 471 as having been used to protect payloads for the Conti, Egregor, Mount Locker, Quantum, and Hive ransomware operations, with a 'SPECTRE BOT Runtime Test' update in April 2026; and memory_lost (aliases CrackingCore, donovanranda), who ran a crypting service from January 2021 until arrest by the Cyber Police of Ukraine on 12 June 2024, allegedly having encrypted BlackMatter, Conti, LockBit, and REvil samples for $100/file or $5,000/month for automated re-encryption.

Across the market, providers advertise Windows Defender/SmartScreen bypass, AMSI bypass, ETW patching, syscall unhooking, sandbox-evasion sleep delays, and registry-based tamper protection, paired with persistence via Run keys, scheduled tasks, services, WMI subscriptions, and BITS jobs, and validate 'fully undetectable' (FUD) status using scanning services such as avcheck.net, scanner.to, and (with detection-leak risk) public VirusTotal submissions. Recorded Future explicitly cautions that provider-advertised evasion claims should be treated as marketing unless corroborated by sample analysis, and that the significance of this market is the commodification and packaging of established tradecraft — not technical novelty.

MITRE ATT&CK techniques used in TL-2026-2014

Defense Evasion

T1027.002 Obfuscated Files or Information: Software Packing; T1027.009 Obfuscated Files or Information: Embedded Payloads; T1036.005 Match Legitimate Resource Name or Location; T1055 Process Injection; T1055.012 Process Injection: Process Hollowing; T1055.013 Process Doppelgänging; T1140 Deobfuscate/Decode Files or Information; T1497 Virtualization/Sandbox Evasion; T1574.001 DLL; T1620 Reflective Code Loading; T1622 Debugger Evasion

Execution

T1106 Native API

defense-impairment

T1112 Modify Registry; T1685 Disable or Modify Tools

Discovery

T1518.001 Software Discovery: Security Software Discovery

Persistence

T1547.001 Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder

Affected products and versions in VIP Crypt and ASMCrypt

  • Microsoft — Windows (Defender/SmartScreen and third-party AV/EDR on Windows client and server)
    Vulnerable versions: All supported Windows client and server versions (crypter evasion is OS-version-agnostic, per provider claims)

Remediation for VIP Crypt and ASMCrypt

Immediate actions

  • Prioritize behavioral detection over static file signatures for packed/obfuscated Windows binaries, since crypter output is designed to defeat hash- and signature-based AV
  • Alert on new Windows Defender/EDR exclusion additions and other security-product tampering or discovery activity
  • Flag unsigned executables launched from temporary, user-writable, or unusual directories, including files staged via short-lived hosting such as Temp.sh
  • Monitor/block the reported AirVPN egress IP 46.183.217.105 and the FTPS delivery endpoints 91.92.242.14:9090 and 5.61.36.246:9090 at the perimeter

Workarounds

  • Avoid public VirusTotal submission of suspicious crypted samples — crypting-service operators monitor public detection ratios and re-crypt/re-issue stubs in response; use private/isolated sandboxing instead

Longer-term hardening

  • Deploy EDR/ETW telemetry capable of detecting manual PE mapping, process hollowing, and process doppelgänging rather than relying on static AV alone
  • Implement application control/allowlisting to block execution of newly written or unsigned binaries in user-writable paths
  • Hunt for Heaven's Gate (x86-to-x64) transitions and direct/indirect syscall usage that bypasses user-mode ntdll hooks
  • Correlate telemetry across known HijackLoader-delivered payload families (Cobalt Strike, LummaC2, RedLine Stealer, Danabot, SystemBC) to catch crypter-wrapped droppers regardless of final payload

Timeline of VIP Crypt and ASMCrypt

  • mrlapis begins operating the VIP Crypt crypting service, per Insikt Group's activity assessment (~15 years of continuous operation, ~$83,000 in estimated proceeds).
  • ImComplexed launches the Private Protector crypter service on the Exploit forum.
  • memory_lost (aka CrackingCore, donovanranda) begins operating a crypting service later linked to BlackMatter, Conti, LockBit, and REvil payloads.
  • memory_lost is apprehended by the Cyber Police of Ukraine, ending that crypting-service operation.
  • Private Protector receives its most recent documented update prior to the report.
  • ImComplexed releases a 'SPECTRE BOT Runtime Test' update to Private Protector.
  • Recorded Future's Insikt Group publishes a report profiling 24 active crypting-service providers, including VIP Crypt (mrlapis) and ASMCrypt (o1oo1) with HijackLoader integration; same-day coverage follows from Cyber Security News, GBHackers, and The Hacker News' ThreatsDay roundup.

Sources cited for VIP Crypt and ASMCrypt

Threats related to VIP Crypt and ASMCrypt

Detection coverage for TL-2026-2014

As of 2026-08-14, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2014 across Splunk SPL, Microsoft KQL and Sigma, covering 19 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats