Published Security3 min read
Crypting grew up: 24 sellers, tiered pricing, and a promise to re-crypt you when you get caught
Recorded Future's Insikt Group counted 24 crypting vendors competing on detection scores and re-crypt turnaround times. That makes a clean AV score a receipt, not a control.
Not a builder's beat, but builders have a standing stake in it.See today for builders

What happened
- Insikt Group analyzed 24 threat actors advertising crypting services and products within the past year and identified a market that is competitive, reputation-driven, and heavily focused on Windows payloads.
- Providers compete through tiered pricing, antivirus (AV) detection scores of crypted samples, discounts, malware-developer partnerships, private or shared stubs, and promised turnaround times for re-crypting detected payloads.
- Crypting is a service or product in which a file, almost exclusively a malicious executable, is encrypted to bypass malware detection technologies; basic crypting consists of encrypting or obfuscating a customer-supplied payload.
- Mature providers increasingly operate as broader malware-enablement services, with offerings that combine payload wrapping, in-memory execution, anti-analysis checks, process injection, persistence options, delivery packaging, and post-detection cleaning or re-crypting services.
- Because crypted payloads are designed to defeat both static and dynamic analysis, defenders should prioritize behavioral detection over static indicators.
Compiled by The WatchSomething wrong?How this is made
Why it matters
Recorded Future's Insikt Group analyzed 24 threat actors advertising crypting services and products over the past year and described what it found as a competitive, reputation-driven market [1]. It matters because those sellers compete on the same number many defenders quietly use to reassure themselves: the antivirus detection score of a crypted sample [2].
Crypting, in the narrow sense, is the service of encrypting or obfuscating a customer-supplied executable so it bypasses malware detection technology [3]. The report's point is that the narrow sense no longer describes the market. Mature providers operate as broader malware-enablement services, bundling payload wrapping, in-memory execution, anti-analysis checks, process injection, persistence options, delivery packaging, and post-detection "cleaning" or re-crypting [4]. According to Insikt Group, providers differentiate on tiered pricing, detection scores, discounts, partnerships with malware developers, private or shared stubs, and promised turnaround times for re-crypting payloads that have been detected [2].
That last item is the one with operational consequence. A re-crypt guarantee reclassifies detection from a terminal event for the attacker into a warranty claim. The defender's signature still works; it just stops mattering to the customer who has already opened a ticket. Insikt Group does not publish turnaround figures for those promises, so anyone quoting a specific half-life for a signature is guessing.
The evasion is designed to be two-sided. Crypted payloads are built to defeat both static and dynamic analysis, which is why the report tells defenders to prioritize behavioral detection over static indicators [5]. Many services ship execution guardrails and indicator suppression: failing to run in virtual environments, or scanning the environment first to determine whether it is a sandbox or analysis host [6]. Encryption algorithms are often proprietary [7]. Insikt Group states plainly that AV and EDR should not be treated as sufficient standalone protection against crypted payloads, and should be paired with behavioral detection, telemetry correlation, upstream hunting, suspicious process monitoring, and rapid triage of suspicious samples [8].
Two pieces of scope discipline are worth keeping. First, crypting is not intrusion: crypted payloads raise the odds of successful execution and delay detection, but lateral movement, data theft, ransomware deployment, and follow-on compromise still depend on the embedded malware and the operator's objectives [9]. Second, the risk band is wide. Advanced crypters offer portability, anti-analysis, process injection, persistence, and security-product bypass; less capable ones amount to basic obfuscation [10]. The report's own framing is that none of these capabilities is individually novel, and that the significance lies in commercial packaging making mature evasion tradecraft easier to buy, reuse, and operationalize [11].
The platform picture is narrow and probably temporary. Popular providers advertise Windows support, with no advertising identified for macOS or Linux crypting [12], meaning none of the 24 actors reviewed was seen marketing non-Windows coverage [13]. Insikt Group is explicit that this reflects demand rather than any inherent Windows weakness in executing crypted payloads [14]. Distribution is everywhere: underground forums, restricted communities, chat platforms, clearnet sites, and social media accounts [15].
What to watch: whether macOS or Linux crypting advertising surfaces, since that would follow endpoint fleet composition rather than technique; whether providers begin publishing re-crypt turnaround as a formal tier, which would give defenders a measurable adversary service level; and, internally, what share of your last quarter's malware detections came from behavior rather than file signatures. If that ratio is unflattering, the crypting market is already priced against you.
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Insikt Group analyzed 24 threat actors advertising crypting services and products within the past year and identified a market that is competitive, reputation-driven, and heavily focused on Windows payloads.
- [2]
Providers compete through tiered pricing, antivirus (AV) detection scores of crypted samples, discounts, malware-developer partnerships, private or shared stubs, and promised turnaround times for re-crypting detected payloads.
- [3]
Crypting is a service or product in which a file, almost exclusively a malicious executable, is encrypted to bypass malware detection technologies; basic crypting consists of encrypting or obfuscating a customer-supplied payload.
- [4]
Mature providers increasingly operate as broader malware-enablement services, with offerings that combine payload wrapping, in-memory execution, anti-analysis checks, process injection, persistence options, delivery packaging, and post-detection cleaning or re-crypting services.
- [5]
Because crypted payloads are designed to defeat both static and dynamic analysis, defenders should prioritize behavioral detection over static indicators.
- [6]
Many crypting services include execution guardrails or indicator suppression methods, such as ensuring execution fails in virtual environments or performing environmental scanning before execution to determine whether the payload is running in an analysis or sandbox environment.
Sources & coverage · 1 publisher
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- recordedfuture.comAug 12Malware Crypting Services and the Threat Actors Who Sell Them
Additional citations
- Recorded Future / Insikt Group



