Google filed a civil action in the U.S. District Court for the Southern District of New York against alleged CryptBot distributors, accusing named defendants and unidentified operators of running a malware distribution enterprise built around the 360installer pay-per-install network and OffShoric hosting. The company said the group spread CryptBot through cracked-software and fake download sites, including trojanized versions of Google Chrome and Google Earth Pro, and that a federal judge unsealed the case and granted a temporary restraining order to support disruption of current and future distribution domains. Google alleged roughly 670,000 infections over the prior year from the identified sites alone and said the operation harmed Chrome users by stealing credentials, browser cookies, credit card data, social media logins, cryptocurrency wallet information, screenshots, and Chrome extension data for later sale and abuse.
Security research cited across multiple reports shows CryptBot has been a fast-moving infostealer operation for years, repeatedly changing its packing, filenames, scripts, code paths, and command-and-control infrastructure to evade detection while relying heavily on fake cracks, serials, and software installers surfaced in search results. Analysts documented multi-stage delivery using archives, BAT scripts, AutoIt components, and in some campaigns public services such as Bitbucket, where one malicious repository was observed serving malware at volumes suggesting about 40,000 downloads per day before takedown. Recent samples used recurring .top infrastructure and improved browser-theft logic for newer Chrome versions, while also downloading follow-on payloads such as ClipBanker, underscoring that CryptBot functioned not only as a credential thief but as part of a broader malware distribution ecosystem.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
14 events from the most recent confirmed update back to the earliest known activity.
Google said a federal judge in the Southern District of New York unsealed the case and granted a temporary restraining order supporting technical disruption, including takedowns of current and future CryptBot distribution domains.
Google announced a civil action targeting major CryptBot distributors it said were based in Pakistan and spreading the infostealer through trojanized software packages such as fake Google Chrome and Google Earth Pro installers.
OpenAnalysis published technical research on CryptBot, including sample hashes, a YARA rule, Python code to decrypt embedded configuration, and recurring .top /gate.php C2 patterns.
Google alleged that 168,055 computers were infected through the operation from 1 December 2022 through 28 February 2023.
AhnLab ASEC reported a recently modified CryptBot variant that removed several older features but updated Chrome path handling and fixed logic that had prevented successful theft on Chrome 96 and later.
Google's complaint states that CryptBot resurged in early 2022 after having first been identified in 2019.
ASEC reported that the fake software-download ecosystem commonly used to spread CryptBot was also distributing other malware families including RedLine, Vidar, and Remcos, using NSIS droppers and AutoIt-based loaders. The analysis described process hollowing into legitimate Windows binaries and use of intermediary services such as Tumblr to obtain C2 information.
AhnLab ASEC published analysis showing CryptBot being spread through fake software-download pages aimed at users seeking cracks and serials, with frequently changing BAT scripts and .top-domain C2 infrastructure.
AhnLab ASEC reported that CryptBot was being distributed through fake software, crack, and serial-number download sites surfaced in search results. The report documented a newly observed MalPE-packed delivery format, process hollowing execution, and secondary malware downloads including ClipBanker, with observed cases involving Formbook and SmokeLoader.
Atlassian removed the Bitbucket repository on 3 February 2020, about 67 hours after it was reported. The repository had been serving malware at rates that implied more than 355,100 downloads during that interval.
A public Bitbucket repository under the user name Lewis Shields, later used to host CryptBot and other malware, had existed since 16 January 2020.
Google's later court filing states that the CryptBot infostealer was initially identified in 2019.
Google filed a complaint in the U.S. District Court for the Southern District of New York against Zubair Saeed, Raheel Arshad, Mohammad Rasheed Siddiqui, and unidentified operators, alleging they ran the 360installer and OffShoric infrastructure used to distribute CryptBot.
Researchers reported the malware-hosting Bitbucket repository to Atlassian on a Friday afternoon before its eventual removal.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
8 references tracked. Mallory keeps watching after this page renders.
blog.google
Open sourceresearch.openanalysis.net
Open sourceasec.ahnlab.com
Open sourceasec.ahnlab.com
Open sourceasec.ahnlab.com
Open sourceasec.ahnlab.com
Open sourcegdatasoftware.com
Open sourceregmedia.co.uk
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.