Threat Advisory

AceCryptor - A Powerful Cryptor Evading Malware Detection

Threat: Malware
Criticality: High
[subscribe_to_unlock_form]

Summary:

AceCryptor is a cryptor-as-a-service (CaaS) that has been used by malware authors since 2016 to protect their creations against detection. It has been used to pack tens of malware families and is known by various names. Researchers detected over 80,000 unique samples of AceCryptor between 2021 and 2022, indicating its prevalence in the wild. The malware families packed by AceCryptor include SmokeLoader, RedLine Stealer, RanumBot, Raccoon Stealer, STOP ransomware, Amadey, Fareit, Pitou, Tofsee, Taurus, Phobos, Formbook, Danabot, Warzone, and more.[/subscribe_to_unlock_form]

Summary:

AceCryptor is a cryptor-as-a-service (CaaS) that has been used by malware authors since 2016 to protect their creations against detection. It has been used to pack tens of malware families and is known by various names. Researchers detected over 80,000 unique samples of AceCryptor between 2021 and 2022, indicating its prevalence in the wild. The malware families packed by AceCryptor include SmokeLoader, RedLine Stealer, RanumBot, Raccoon Stealer, STOP ransomware, Amadey, Fareit, Pitou, Tofsee, Taurus, Phobos, Formbook, Danabot, Warzone, and more.[emaillocker id="1283"]

AceCryptor is distributed through trojanized installers of pirated software, spam emails with malicious attachments, and other malware that downloads new malware protected by AceCryptor. It uses a multistage, three-layer architecture with obfuscations to evade detection. The first layer decrypts the second layer using either TEA (Tiny Encryption Algorithm) or a linear congruential generator (LCG). The second layer is shellcode which performs defensive tricks and decrypts the third layer. The third layer is more shellcode that performs anti-investigation tricks and launches the payload. The obfuscations in AceCryptor include the use of loops with junk code to confuse analysts, delay execution, and hide important operations. The second layer adds additional encryption and protection to the third layer. The third layer uses process hollowing or a reflective loader to launch the final payload.

AceCryptor's first layer uses loops with junk code, delay techniques, and hiding important operations within loops. The second layer adds anti-sandbox/anti-emulator checks using file system attributes and window creation APIs. The third layer includes an additional anti-sandbox/anti-emulator check using message passing APIs. AceCryptor also employs process hollowing, reflective code loading, and other techniques to evade detection and analysis.

AceCryptor has been detected in various countries around the world, and ESET products have blocked malware variants packed by AceCryptor on over 80,000 customers' computers. The high number of unique samples of AceCryptor highlights the active efforts of its authors in obfuscation and detection evasion. Many malware authors rely on cryptor services like AceCryptor instead of implementing their own cryptor solution.

Threat Profile:

References:

The following reports contain further technical details:

https://www.welivesecurity.com/2023/05/25/shedding-light-acecryptor-operation/

[/emaillocker]
crossmenu