typetechniqueconfidencehighcreated2026-07-26updated2026-07-26cryptographypayload-decryptionaes-gcmbcryptwindows-cngdefence-evasion

BCrypt AES-GCM Payload Decryption

Use of the Windows Cryptography API: Next Generation (CNG) — specifically bcrypt.dll — to AES-GCM decrypt a downloaded or embedded payload, avoiding custom crypto implementations that might be easier to fingerprint.

Mechanism

  1. BCryptOpenAlgorithmProvider with BCRYPT_AES_ALGORITHM.
  2. BCryptSetProperty with ChainingModeGCM property string.
  3. BCryptGenerateSymmetricKey or BCryptImportKey.
  4. BCryptDecrypt (or BCryptEncrypt for outbound traffic).

Why It Matters

Malware authors increasingly use OS-native crypto primitives rather than statically linking OpenSSL or rolling their own. This:

  • Reduces binary size and entropy.
  • Blends with legitimate Windows cryptographic traffic.
  • Makes static key extraction harder when keys are derived at runtime (e.g. via PBKDF2 or ECDH).

Observed Implementations

  • Sample 60996777bf4f37e0eec2a99d450664278f103077f12a4b59178ff240ccb1b803 (unclassified-mingw64-https-stager) imports BCryptEncrypt, BCryptDecrypt, BCryptGenerateSymmetricKey and carries the ChainingModeGCM string. Coupled with HMAC-SHA256 (software implementation) for payload integrity. ^[strings.txt:260] ^[r2:imports]

Detection / Fingerprint

  • ETW Provider Microsoft-Windows-Crypto-CNG events for BCryptDecrypt with AES-GCM.
  • Memory regions recently written by InternetReadFile that are passed directly into BCryptDecrypt without disk write.

Defensive Countermeasures

  • API hooking on BCryptDecrypt in suspicious processes (e.g. those that also called InternetReadFile).
  • Memory forensics: hunt for GCM IV + tag structures in process heaps.