# Crypter-as-a-Service Obfuscation Enabling Undetectable Android/Mobile Malware (ASD-led Advisory "Digital camouflage: crypters make malware undetectable")

> A joint advisory from the Australian Signals Directorate with the AFP, New Zealand Police, Google and the UK NCA (first published 8 September 2026) warns that commercial crypters, sold as a service from about $25-$30 per file, let cybercriminals make malware 'fully undetected'. Zimperium's 7 October 2026 analysis ties this to Android banking trojans (RecruitRat, SaferRat, Astrinox, Massiv) that target 800+ banking, crypto and social apps, and to 34 active mobile families targeting 1,243 financial brands in 90 countries.

- **Published:** 2026-10-07T00:00:00Z
- **Last reviewed:** 2026-10-07T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-3033
- **ID:** TL-2026-3033
- **Severity:** HIGH
- **Category:** MALWARE
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 21 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Crypters are tools or services that transform a malware file so that antivirus, EDR, mobile threat defense and network monitoring do not recognise it. The Australian Signals Directorate (ASD), Australian Federal Police (AFP), New Zealand Police, Google and the UK National Crime Agency (NCA) published the advisory 'Digital camouflage: crypters make malware undetectable' on 8 September 2026. It describes crypter-as-a-service (CaaS) as part of the cybercrime business model: financially motivated operators advertise on dark web forums, and criminals who already hold malware buy crypting to improve campaign success. Security vendors share malware intelligence via platforms such as VirusTotal, and crypters are the adversary response to that sharing.

Per Zimperium's 7 October 2026 write-up of the advisory, pricing runs from $25-$30 per file at the entry level, through $500-$3,000 per month subscriptions, to $12,000-$20,000 per month for premium tiers with rapid re-obfuscation. Zimperium attributes these figures to Recorded Future Insikt Group research (August 2026) covering 24 active vendors. At least two vendors advertise APK crypting for Android, and one claims Google Play Protect evasion. Android obfuscation-as-a-service has been documented since 2020. Zimperium reports 34 active mobile malware families targeting 1,243 financial brands across 90 countries. The article names advisory-relevant evasion techniques: APK tampering and packers, encrypted payloads and dynamic code loading, environment-aware execution, anti-emulation and anti-analysis checks, native-code obfuscation, and LLM-based code regeneration to vary signatures per execution.

Zimperium's April 2026 research on four Android banking trojan campaigns shows the downstream effect. RecruitRat spreads through fake job-application sites, uses HTTPS C2 with an RC4 layer, a per-victim BotID, DexClassLoader payload loading, ZIP-structure manipulation with unsupported compression methods, and an 'injectZip' command delivering 700+ HTML overlay templates. SaferRat spreads through fake free-streaming sites and loads WebView phishing payloads from remote endpoints, hiding stages in res/ or assets/ and using malformed ZIP headers and very long filenames to break analysis tools. Astrinox (tracked by Cleafy as Mirax) imitates the HireX recruitment platform on xhire.cc, uses WebSocket C2, and decrypts an AES/GCM-protected core payload in memory before running it from the cache folder. Massiv aborts on rooted devices or when mobile antivirus is detected. All four abuse Accessibility Services, MediaProjection screen streaming and overlay or fake 'Android Update' screens. Zimperium reported near-zero signature-based detection for these samples. A later Zimperium campaign set ('RecruitTrap', August 2026) lists a large set of lookalike '-careers' and '-global' domains.

The advisory names no specific crypter service, CVE or threat actor. Zimperium indicators are published in its public GitHub IOC repository. Recorded Future's reporting, as summarised by third parties, links CaaS to malware including PureRAT, FvncBot, Albiriox, Mirax and GhostCrypt. The ASD advisory's recommendations are generic (awareness of evolving malware concealment, regular review of defensive controls, proactive monitoring). Defenders should therefore favour behavioural and runtime detection over hash or signature matching for Android banking malware.

## MITRE ATT&CK

- T1660 Phishing
- T1583.001 Acquire Infrastructure: Domains
- T1588 Obtain Capabilities
- T1027 Obfuscated Files or Information
- T1406.002 Obfuscated Files or Information: Software Packing
- T1407 Download New Code at Runtime
- T1633.001 Virtualization/Sandbox Evasion: System Checks
- T1655.001 Masquerading: Match Legitimate Name or Location
- T1626.001 Abuse Elevation Control Mechanism: Device Administrator Permissions
- T1453 Abuse Accessibility Features
- T1417.002 Input Capture: GUI Input Capture
- T1417.001 Input Capture: Keylogging
- T1517 Access Notifications
- T1513 Screen Capture
- T1636.004 Protected User Data: SMS Messages
- T1426 System Information Discovery
- T1481.002 Web Service: Bidirectional Communication
- T1629.002 Impair Defenses: Device Lockout

## Sources

- [Crypters and the Mobile Malware Blind Spot: What a New Australian Government Advisory Means for Mobile Security (Zimperium)](https://zimperium.com/blog/crypters-and-the-mobile-malware-blind-spot-what-a-new-australian-government-advisory-means-for-mobile-security)
- [ASD advisory: Digital camouflage: crypters make malware undetectable](https://cyber.gov.au/about-us/view-all-content/alerts-and-advisories/digital-camouflage-crypters-make-malware-undetectable)
- [Digital camouflage: crypters make malware undetectable (advisory PDF)](https://www.cyber.gov.au/sites/default/files/2026-09/digital_camouflage_crypters_make_malware_undetectable.pdf)
- [Digital camouflage: how crypters hide malware (ASD news)](https://www.cyber.gov.au/about-us/view-all-content/news/digital-camouflage-how-crypters-hide-malware)
- [Android Bankers: 4 Campaigns in a Row (Zimperium zLabs)](https://zimperium.com/blog/android-bankers-4-campaigns-in-a-row)
- [Zimperium IOC repository (2026-04-Multiple-Bankers, 2026-08-RecruitTrap)](https://github.com/Zimperium/IOC)
- [4 new Android malware families target 800 apps (SC Media)](https://www.scworld.com/brief/4-new-android-malware-families-target-800-apps)
- [Australia issues cyber advisory on crypters used to hide malware (OpenGovAsia)](https://opengovasia.com/australia-issues-cyber-advisory-on-crypters-used-to-hide-malware/)
- [Digital camouflage: crypters make malware undetectable (ThreatBeat alert)](https://threatbeat.com/alert/digital-camouflage-crypters-make-malware-undetectable/)
- [2 Arrested for Operating Malware Encryption Service (CyberSeal, Dataprotector, Cyberscan)](https://www.bankinfosecurity.com/2-arrested-for-operating-malware-encryption-service-a-15426)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-3033
