Skip to content

Malware

CrackedCantil

According to ANY.RUN, this is a dropper for win.privateloader and its execution will lead to a cascade of downloads with a large variety of additional malware.

CrackedCantil is a Windows malware family.

Background

ANY.RUN describes this as a dropper for win.privateloader whose execution triggers a chain of downloads pulling in a broad assortment of further malware. The delivered families span additional loaders, information stealers, cryptominers, a proxy bot, and eventually ransomware as well. The sequence is deliberately orchestrated, for instance so that data is harvested and exfiltrated before encryption begins. Distribution occurs via advertised cracked software such as IDA Pro.


Source: Malpedia (Fraunhofer FKIE).