CryptBot is a Windows infostealer focused on harvesting sensitive user and system data from infected hosts. It is commonly distributed through fake software-download ecosystems, especially sites masquerading as sources for cracks, key generators, activators, serials, and free versions of commercial software. Operators have also used trojanized installers, including altered activators and modified software packages, and have relied on search-engine manipulation to drive victims to malicious landing pages. CryptBot has also appeared in broader commodity-malware delivery campaigns and in some cases has been delivered through loader or sideloading chains rather than directly.
The malware steals browser-stored credentials, cookies, browsing data, credit card information, and cryptocurrency-wallet data, and has also been observed collecting system profiling information and, in some versions, screenshots and selected files. Targeted applications have included major Chromium-based browsers and Firefox-family browsers, along with numerous desktop cryptocurrency wallets and wallet-related browser extensions. Stolen data is typically staged, often compressed into an archive, and exfiltrated to command-and-control infrastructure. Some variants also download and execute secondary payloads, most notably ClipBanker, and observed follow-on payloads have included other commodity malware.
CryptBot operators frequently change packing, loaders, filenames, scripts, and infrastructure to reduce detection. Reported execution chains include multi-layer archives, self-extracting packages, AutoIt-based loaders, in-memory decryption, manual DLL loading, and process hollowing or related injection techniques. Anti-analysis and defense-evasion behaviors reported across variants include anti-VM or anti-sandbox checks, duplicate-infection checks, self-deletion in some versions, obfuscation, and limited disk artifacts through in-memory execution. Infrastructure patterns have repeatedly involved rapidly rotated command-and-control servers, often using short-lived domains.
CryptBot has been active since at least 2019 and has been associated with large-scale criminal distribution operations affecting hundreds of thousands of systems. Public reporting and civil litigation have linked major distribution activity to cracked-software ecosystems and operators based in Pakistan. The malware is broadly opportunistic, but campaigns have particularly targeted users seeking pirated software and, in some reporting, users of Google Chrome because of the stealer’s emphasis on browser data theft.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Mandiant analyzed the workstations belonging to the end user and discovered that some systems had been infected with CRYPTBOT, an info-stealer malware, shortly before the stolen session token was generated.
25 distinct techniques documented for this family, organized by ATT&CK tactic.
Because Cryptbot’s operation doesn’t rely on the existence of unencrypted binaries on the disk, detecting it is only possible by monitoring for malicious behavior such as PowerShell command execution or external network communication.
The downloader includes defenses against reverse engineering and automated string extraction... To hinder automatic extraction, the last 6 to 8 bytes of each URL are append to the URL, making the string difficult to extract statically. | A new variant featuring enhanced cryptography was recently released... The only cryptographic operation in the malware is performed on the data returned by the server... The data returned by the server is AES-CBC encrypted, with the encryption key derived using PBKDF2-SHA1.
Only the main function, which is responsible for calling the curl API, decrypting, and loading the DLL, has its control flow obfuscated... the code is obfuscated using an extensive switch-case structure.
The adversaries install KMSPico also, because that is what the victim expects to happen, while simultaneously deploying Cryptbot behind the scenes.
The injection of the Cryptbot bytes into memory occurs through the process hollowing method
The injection of the Cryptbot bytes into memory occurs through the process hollowing method
Cryptobot checks for the presence of "%APPDATA%\Ramson," and executes its self-deletion routine if the folder exists to prevent re-infection.
This installer then launches a script that is also heavily obfuscated, which is capable of detecting sandboxes and AV emulation, so it won't execute when run on the researcher's devices.
It functions as a stealer malware, capturing sensitive information like login credentials, browser cookies, and cryptocurrency wallet data.
CryptBot malware steals infected PC’s information as well as various user information and sends them to the server.
462 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
37 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
CryptBot1
A stealer malware family explicitly listed as distributed by RUGMI/IDAT Loader.
In another campaign identified by Trellix, DLL sideloading was used to distribute a wide assortment of malware, such as Agent Tesla, CryptBot, Formbook, Lumma Stealer, Vidar Stealer, Remcos RAT, Quasar RAT, DCRat, and XWorm.
"...DLL sideloading was used to distribute a wide assortment of malware, such as Agent Tesla, CryptBot, Formbook, Lumma Stealer, Vidar Stealer, Remcos RAT, Quasar RAT, DCRat, and XWorm."
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.