A refreshed CryptBot campaign has been distributing a Windows infostealer through websites posing as sources for cracked software, key generators, and free game or professional software downloads. The malware steals browser credentials, cookies, browsing history, cryptocurrency wallet data, credit card information, and files from infected systems, while operators use SEO poisoning and rapidly rotated lure sites and command-and-control infrastructure to drive victims to malicious downloads. Reporting indicates the malware was heavily associated with users seeking pirated software, and telemetry in one analyzed campaign suggested Russia was a primary target.
Technical analysis of a newer CryptBot downloader shows a 32-bit statically linked sample using libcurl 8.10.1 and OpenSSL 3.3.2, with evolving obfuscation that includes modified plaintext C2 URLs and control-flow tricks in the main routine. The downloader fetched an encrypted second-stage DLL over unencrypted HTTP from .top domains, then decrypted it with AES-CBC using a PBKDF2-SHA1-derived key built from the server-provided filename, the URL, and a static key suffix embedded in the sample. Researchers also noted the malware had been streamlined by removing some older anti-analysis and collection features while improving Chrome data theft so it could extract information across all Chrome versions rather than a limited version range.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
TEHTRIS disclosed technical details on a CryptBot downloader variant, including its HTTP-based stage-two retrieval, AES-CBC/PBKDF2 decryption scheme, C2 infrastructure, hashes, and YARA and Snort detection content. The report also noted that identified C2 servers had been frequently shut down and were unavailable at the time of writing.
Google released Chrome 96, a milestone that later exposed a limitation in older CryptBot versions that relied on fixed Chrome user-data paths.
TEHTRIS analyzed a recent CryptBot downloader campaign that lasted about one month based on PE compilation timestamps, with activity peaking roughly one week after it began. Russia appeared to be the primary targeted country based on VirusTotal first-submission data.
Ahn Lab reported a new CryptBot variant being spread through fake crack, keygen, and free-download sites promoted with SEO poisoning. The updated malware removed several older functions while improving Chrome data theft by searching all paths for Chrome user data.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.