Shanya Packer Is Becoming the New Weapon of Choice for Ransomware Gangs

Listen to this Post

Featured Image

Introduction

A new packer-as-a-service platform named Shanya is rapidly reshaping the cybercrime landscape. First observed near the end of 2024, this covert tool has already become a favorite among high-profile ransomware gangs that want to bypass modern endpoint detection and response protections. Shanya hides malicious code inside seemingly harmless Windows components, making the payload almost impossible for automated defense systems to flag. As global attacks surge, security analysts warn that this new packer represents not just another tool in the ransomware ecosystem but a strategic shift in how cybercriminals hide, deliver, and execute destructive malware.

Summary of the Original

Rise of a New Packer Service

Security researchers have identified a packer-as-a-service called Shanya, now widely used by ransomware operators to conceal and deploy highly evasive malicious payloads.

Purpose of Packer Services

Packer services offer cybercriminals the ability to wrap their malware with layers of obfuscation, compression, and encryption, allowing the payload to bypass most antivirus tools and security scanners.

Global Detection Spike

Shanya began circulating in late 2024 and has since increased sharply in visibility. Telemetry from Sophos Security shows malware using Shanya has been spotted in Tunisia, Nigeria, the UAE, Costa Rica, and Pakistan, indicating a fast global spread.

Adoption by Major Ransomware Gangs

Several notorious ransomware groups now rely on Shanya. Confirmed adopters include Medusa, Qilin, Crytox, and Akira. Akira appears to be using the service more aggressively than the others.

How Attackers Use Shanya

Threat actors upload their malware to Shanya, and the platform returns an encrypted and compressed version wrapped in a custom loader. Each buyer receives a unique stub that uses a distinct encryption algorithm.

Use of a Windows System DLL as a Decoy

The payload is injected into a memory-mapped copy of the Windows shell32.dll. The file keeps a legitimate appearance, but its header and critical sections are replaced with the decrypted malicious code. The entire process occurs only in memory, never touching disk.

Stealth Techniques Against EDR Tools

Shanya disrupts EDR analysis by abusing the RtlDeleteFunctionTable call in an invalid context. This creates crashes or unhandled exceptions in debuggers, preventing full behavioral inspection.

Disabling Security Before Encryption

Ransomware operators typically try to disable EDR software before stealing data or encrypting files. Shanya helps them achieve this through DLL side-loading, using clean Windows executables like consent.exe paired with malicious Shanya-wrapped DLLs.

Use of Rogue Drivers

Sophos observed that the EDR killer linked to Shanya deploys two drivers:

a legitimately signed ThrottleStop.sys from TechPowerUp, which contains a kernel memory write flaw used for privilege escalation,

an unsigned hlpdrv.sys driver used to disable security tools.

Automated Process and Service Termination

A user-mode component scans running services and processes, compares them to a built-in target list, and instructs the kernel driver to terminate them.

Used Beyond Ransomware

Shanya is also appearing in ClickFix campaigns distributing CastleRAT, indicating the packer is expanding beyond classic ransomware uses.

Why Packer Services Matter

Sophos confirms ransomware gangs increasingly rely on packers like Shanya to prepare and deliver EDR killers without raising alarms.

Technical Resources Provided

The security report includes indicators of compromise and detailed analysis of Shanya-packed payloads.

How Shanya Is Transforming Cybercrime Tactics

A New Generation of Malicious Packaging Tools

Shanya’s value lies in its cellular-level uniqueness. Traditional packers recycle similar stubs, but Shanya promises each buyer a distinct encryption wrapper and loader. This uniqueness greatly reduces signature-based detection opportunities for defenders.

Memory-Only Execution as a Standard Feature

Most modern malware tries to avoid touching the disk, but Shanya elevates this method into a built-in feature. The payload is decrypted inside a memory-mapped shell32.dll clone, which looks clean from the outside. On disk, shell32.dll remains unchanged. Inside memory, it becomes a weapon.

Built to Break Automated Analysis

By triggering controlled exceptions in debuggers, Shanya disrupts automated sandboxing systems. Operators essentially force tools like automated EDR sandboxes to crash before they can observe malicious activity. This creates a safety bubble around the malware until it is fully executed on the victim machine.

Leveraging a Legitimate Driver for Escalation

The use of the ThrottleStop.sys driver is a striking example of threat actors twisting legitimate software into an attack vector. Signed drivers are extraordinarily difficult for security systems to block because they appear authentic. Shanya operators exploit this trust to gain kernel-level write access.

EDR Kill Chains as a Priority Target

Modern ransomware operators know that encryption alone is no longer enough. With strong backups and recovery systems in place, attackers increasingly focus on disabling EDR to maintain persistence, bypass detection, and ensure data exfiltration. Shanya automates a major portion of this kill chain.

A Pivot Toward Multi-Region Campaigns

The global footprint of Shanya-linked attacks shows that this tool is not geographically limited. Its rapid adoption hints at a business model that is expanding fast across criminal groups searching for stealth advantages.

What Undercode Say:

Shanya is more than a packer. It is an ecosystem-level weapon designed to break the detection models security defenders rely on. Its per-client unique stubs mean that every attack looks different, every payload is individually wrapped, and every kernel interaction appears novel. This dramatically weakens signature-based defenses and allows ransomware operators to blend into legitimate system behavior.

Its memory-only decryption model bypasses nearly all traditional scanning mechanisms. This approach ensures that disk forensics, endpoint scanners, and even many behavioral engines cannot capture meaningful artifacts. Shanya essentially weaponizes the space between disk and memory, a blind spot in many enterprise security stacks.

The misuse of signed drivers is especially worrying. Enterprises trust signed drivers, and threat actors know this. By embedding privilege escalation inside a legitimate driver, Shanya removes one of the biggest hurdles in modern attacks: gaining kernel access. Once in the kernel, disabling EDR is trivial.

The presence of ClickFix and CastleRAT campaigns shows that Shanya will not remain limited to ransomware. Any criminal group that needs stealth can adopt it. As the underground market evolves, we should expect more modular, service-based components that mimic legitimate software delivery pipelines.

Shanya represents the next iteration of crimeware-as-a-service. It lowers the barrier to entry for attackers, hides operational footprints, and grants kernel-level power through commodity tools. Defenders will need to pivot toward memory forensics, kernel telemetry, and anomaly detection models that do not rely solely on signatures or file analysis. The rapid adoption indicates that Shanya is not a passing trend but a new baseline for advanced cybercrime operations.

Fact Checker Results

Shanya emerged in late 2024 and is confirmed by Sophos Security. ✅

Ransomware groups using the packer include Medusa, Qilin, Crytox, and Akira. ✅

The platform uses shell32.dll memory injection as described. Verified via technical analysis. ✅

Prediction

Cybercriminal adoption of Shanya will continue rising in 2025 as ransomware groups seek stealthier distribution tools. 🔐
We will likely see new variants offering deeper kernel interaction and AI-evading behavior, increasing detection challenges. ⚠️
Defenders will shift toward memory forensics and kernel-level monitoring to close the gap Shanya currently exploits. 🛡️

🕵️‍📝✔️Let’s dive deep and fact‑check.

References:

Reported By: www.bleepingcomputer.com
Extra Source Hub (Possible Sources for article):
https://www.facebook.com
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2
Bing

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow UndercodeNews & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon