A China-linked cybercrime group, previously targeting Indian taxpayers with phishing lures, has been observed using a sophisticated crypter service named Cruciferra. This service is utilized by various cybercriminal threat clusters to distribute a wide range of remote access trojans (RATs) and information stealer malware.
Cruciferra, written in Mono, incorporates numerous techniques to evade detection, analysis, and incident response. These include indirect system calls, API and Import Address Table (IAT) unhooking, and bring-your-own-vulnerable-driver (BYOVD)-based EDR tampering. It also features privilege escalation, persistence mechanisms, and a customized implementation of Process Ghosting to execute payloads while minimizing forensic artifacts.
The crypter emphasizes payload protection and supports custom encryption routines that appear to be dynamically derived and assembled from established cryptographic algorithms. This introduces variations between samples, complicating static analysis and signature-based detections. Researchers note that the encryption algorithm varies significantly between samples, suggesting polymorphic generation from elements of well-known hashing, PRNG, and cipher algorithms.
Cruciferra has been advertised on the cybercrime underground as the "most lethal crypter" for $450 to $2,000 per month, first becoming available in fall 2025. It has been used to distribute commodity malware families such as Agent Tesla, AsyncRAT, DarkCloud Stealer, Formbook, Phantom Stealer, Remcos RAT, Snake Keylogger, ValleyRAT, XLoader, XWorm, and zgRAT. Phishing is the primary initial access vector for campaigns leveraging this crypter, which can either drop an encrypted payload to disk or download it from a staging server.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
A new analysis by Proofpoint details Cruciferra, a sophisticated crypter service used by various cybercriminal groups to deliver malware. Cruciferra employs techniques like BYOVD and Process Ghosting to evade detection and analysis, complicating forensic efforts and static analysis.