Cybercriminals using FUD (Fully Undetectable) crypter services for malwares: Interpol Report

INTERPOL's Industrialization of Cybercrime report uses FUD once, as Fully Undetectable: crypter, packer, and anti-detection services sold so malware looks clean to antivirus and endpoint tools. Vendors re-wrap files, test them until scanners report them clean, and sell that result per test or by monthly subscription, often with proxies, VPNs, and anti-detect browsers. The report gives no FUD price, volume, or named product.
INTERPOL's report The Industrialization of Cybercrime uses FUD once.
In the planning-phase section on crypters, evasion, and obfuscation tools, vendors advertise builds as FUD (Fully Undetectable): malware that antivirus and endpoint products do not flag.
That is not the management phrase fear, uncertainty, and doubt.
A later chapter, Exploit fear and doubt, is a separate idea.
It is about raising risk so criminal markets trust their own tools and partners less.
The report never calls that chapter FUD.
Operation Cronos and LockBit belong there, not to undetectable malware.
Where FUD sits
The report splits criminal services into planning, execution, and aftermath.
Crypters and Evasion Tools sit in planning, next to malware developers and dropper-as-a-service (printed page 9).
Crypter developers are listed with initial access brokers and malware vendors as principal enablers (printed page 8).
The executive summary treats evasion tools as something offenders buy so they do not have to build them (printed page 7).
The definition is in section 2.1, on printed page 10.
For cyber-dependent crime, that planning bucket maps to Kill Chain reconnaissance and weaponization, and to MITRE ATT&CK Initial Access.
Crypters are preparatory tooling, not an execution platform such as phishing-as-a-service.
What is FUD as a service
Crypters, packers, and anti-detection tools are sold to help malware evade antivirus and endpoint detection.
Operators re-wrap files, test them against scanners until the files look clean, and offer those versions as FUD.
Sales are per test or by monthly subscription.
The report says they are often paired with proxy networks, VPNs, and anti-detect browsers, citing Recorded Future on Lumma affiliates (20 August 2025).
The report names no crypter product, FUD price, or detection rate.
On the same page, Lumma Stealer subscriptions of USD 250 to 1,000 are infostealer prices from the May 2025 FBI and Europol disruption, not crypter prices.
The point in the text is commercial defense evasion as a planning input.
Enabling services are themselves criminal, and they let less-skilled actors outsource work they cannot do.
FUD is one such purchase: a claim that a re-wrapped file looks clean, often combined with separate anonymity tools.
What defenders should take from it
The report gives no evasion-success rate.
What it describes is repeated re-wrapping until a scanner result looks clean.
That quiet result is the product being sold, not proof a sample is benign.
Hash- and signature-only checks are weak against a service whose output is a new wrap of an old payload.
Behavior still matters when reputation is quiet.
That is an implication of the service, not a statistic the report measured.
File evasion and network or browser hiding are bought separately and then combined.
Stopping at the payload misses the access layer.
A proxy, VPN, or anti-detect browser is not, by itself, a FUD finding.
Crypter developers are supply-chain enablers, not the operator of one campaign.
A case that names only the end malware understates the service.
Per-test and monthly sales imply repeat customers, which fits the report's argument that shared enablers are the choke point.
It names no crypter takedown, jurisdiction, or FUD marketplace.
What is not in the FUD passage
No volume, price, country, malware family, or named operation is given for FUD.
Genesis Market, disrupted in 2023, is an initial-access example on the same page, not a crypter market.
Section 3.3 (printed page 21) covers trust erosion in criminal markets, with Operation Cronos against LockBit in February 2024.
Those facts are not a FUD trend.
The report does not describe how a crypter works, and this article does not either.
Written by: Cyber Security Team, Ministry of Cyber Affairs