BCrypt AES-GCM Payload Decryption
Use of the Windows Cryptography API: Next Generation (CNG) — specifically bcrypt.dll — to AES-GCM decrypt a downloaded or embedded payload, avoiding custom crypto implementations that might be easier to fingerprint.
Mechanism
BCryptOpenAlgorithmProviderwithBCRYPT_AES_ALGORITHM.BCryptSetPropertywithChainingModeGCMproperty string.BCryptGenerateSymmetricKeyorBCryptImportKey.BCryptDecrypt(orBCryptEncryptfor outbound traffic).
Why It Matters
Malware authors increasingly use OS-native crypto primitives rather than statically linking OpenSSL or rolling their own. This:
- Reduces binary size and entropy.
- Blends with legitimate Windows cryptographic traffic.
- Makes static key extraction harder when keys are derived at runtime (e.g. via PBKDF2 or ECDH).
Observed Implementations
- Sample
60996777bf4f37e0eec2a99d450664278f103077f12a4b59178ff240ccb1b803(unclassified-mingw64-https-stager) importsBCryptEncrypt,BCryptDecrypt,BCryptGenerateSymmetricKeyand carries theChainingModeGCMstring. Coupled with HMAC-SHA256 (software implementation) for payload integrity. ^[strings.txt:260] ^[r2:imports]
Detection / Fingerprint
- ETW Provider
Microsoft-Windows-Crypto-CNGevents forBCryptDecryptwith AES-GCM. - Memory regions recently written by
InternetReadFilethat are passed directly intoBCryptDecryptwithout disk write.
Defensive Countermeasures
- API hooking on
BCryptDecryptin suspicious processes (e.g. those that also calledInternetReadFile). - Memory forensics: hunt for GCM IV + tag structures in process heaps.