Threat Group Cards: A Threat Actor Encyclopedia Archived: 2026-04-06 00:36:44 UTC Home > List all groups > List all tools > List all groups using tool Crypta Tool: Crypta Names Crypta Category Malware Type Loader Description (Kaspersky) Dropping Elephant introduced a new loader for BADNEWS, a tool we named Crypta. It contains mechanisms to hinder detection and appears to be a core component of this APT actor’s recent toolset. Crypta and its variants have been observed in multiple scenarios loading a wide range of subsequent payloads, such as Bozok, QuasarRAT and LokiBot. Information Last change to this tool card: 16 May 2021 Download this tool card in JSON format All groups using tool Crypta Changed Name Country Observed APT groups Patchwork, Dropping Elephant 2013-Jun 2025 1 group listed (1 APT, 0 other, 0 unknown) Source: https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=93641ded-4ae6-488e-9c32-60aa9460fb22 https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=93641ded-4ae6-488e-9c32-60aa9460fb22 Page 1 of 1