← All stories
● Covered by 1 source · 1 reportMedium impact1 negative

Cruciferra Crypter Uses BYOVD and Process Ghosting to Evade Detection

🔄 Updated 1d ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Cruciferra is a crypter service used by cybercriminals.
  • It uses BYOVD and Process Ghosting for evasion.
  • The service supports various custom encryption routines.
  • It has been advertised for $450 to $2,000 per month.

Cruciferra Crypter Emerges

A China-linked cybercrime group, previously targeting Indian taxpayers with phishing lures, has been observed using a sophisticated crypter service named Cruciferra. This service is utilized by various cybercriminal threat clusters to distribute a wide range of remote access trojans (RATs) and information stealer malware.

Advanced Evasion Techniques

Cruciferra, written in Mono, incorporates numerous techniques to evade detection, analysis, and incident response. These include indirect system calls, API and Import Address Table (IAT) unhooking, and bring-your-own-vulnerable-driver (BYOVD)-based EDR tampering. It also features privilege escalation, persistence mechanisms, and a customized implementation of Process Ghosting to execute payloads while minimizing forensic artifacts.

Polymorphic Encryption

The crypter emphasizes payload protection and supports custom encryption routines that appear to be dynamically derived and assembled from established cryptographic algorithms. This introduces variations between samples, complicating static analysis and signature-based detections. Researchers note that the encryption algorithm varies significantly between samples, suggesting polymorphic generation from elements of well-known hashing, PRNG, and cipher algorithms.

Widespread Distribution and Cost

Cruciferra has been advertised on the cybercrime underground as the "most lethal crypter" for $450 to $2,000 per month, first becoming available in fall 2025. It has been used to distribute commodity malware families such as Agent Tesla, AsyncRAT, DarkCloud Stealer, Formbook, Phantom Stealer, Remcos RAT, Snake Keylogger, ValleyRAT, XLoader, XWorm, and zgRAT. Phishing is the primary initial access vector for campaigns leveraging this crypter, which can either drop an encrypted payload to disk or download it from a staging server.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~7 min · 6 stories · Aug 15

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

A new analysis by Proofpoint details Cruciferra, a sophisticated crypter service used by various cybercriminal groups to deliver malware. Cruciferra employs techniques like BYOVD and Process Ghosting to evade detection and analysis, complicating forensic efforts and static analysis.