Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

Microsoft Patches Record 622 Flaws, Including Two Zero-Days Under Active Attack

July 21, 2026

From FBI Cybercrime to Barbie’s CISO: a Leadership Story

July 21, 2026

New HollowGraph Malware Hijacks Microsoft 365 Calendars for Covert C2

July 20, 2026
Facebook X (Twitter) Instagram
Tuesday, July 21
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»Cruciferra Crypter Uses Process Ghosting to Evade Detection
News

Cruciferra Crypter Uses Process Ghosting to Evade Detection

Team-CWDBy Team-CWDJuly 20, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


A crypter service used by multiple unrelated cyber-criminal groups has been documented cloaking commodity malware with process ghosting, kernel-driver abuse and more than 90 mix-and-match encryption routines.

According to new research from Proofpoint published on July 20, the crypter, marketed as Cruciferra, was first offered for sale on the Exploit forum in autumn 2025 and now underpins dozens of campaigns delivering AsyncRAT, Agent Tesla, Remcos, XWorm, ValleyRAT and Snake Keylogger. Tiered access runs from $450 to $2,000 a month.

Proofpoint identified both production and apparent testing samples, suggesting active development.

On dark web forums, Cruciferra calls itself “the underground’s most lethal crypter.” 

Read more on crypter services: Accounting Firm Targeted by Malware Campaign Using New Crypter

Kernel Drivers and Custom Cryptography

In the observed campaigns, Proofpoint said Cruciferra always executed through DLL side-loading. 

Victims received a ZIP pairing a legitimate executable with a malicious DLL. Running the executable side-loaded the DLL, which inspected the environment before dropping the payload. The DLL contained hundreds of decoy exported functions pointing to junk code, with only one or two calling into the real routine.

Before executing, the crypter unhooked endpoint detection and response (EDR) monitoring at multiple levels. It patched the Import Address Table, read a clean copy of ntdll.dll to source indirect syscalls, and disabled kernel-level telemetry by loading a vulnerable signed driver such as GoFlyDrv.sys, then issuing IOCTL commands to terminate security processes.

This bring-your-own-vulnerable-driver (BYOVD) approach mirrors techniques seen in the GentleKiller framework, which the Gentlemen ransomware gang distributes to affiliates.

Payloads sat in the binary’s .reloc section and were unpacked using one of over 90 encryption routines, each assembled from parts of established algorithms including Keccak, Threefish and Feistel variants, so the cipher covering one sample rarely matched the next.

Process Ghosting With Kernel Anti-Peek

For the final execution step, Cruciferra employed a modified form of process ghosting. The classic technique creates a temporary file marked for deletion, fills it with the payload, and uses it as the backing image for a suspended process, leaving a running process backed by a PE image that no longer exists on disk in scannable form.

Cruciferra added two anti-inspection layers. It patched ZwQueryVirtualMemory so EDR queries against the ghosted memory returned a sanitized result, and neutered NtManageHotPatch, the kernel function that can validate a loaded image against its on-disk counterpart.

Proofpoint attributed multiple campaigns using the malware to the Chinese-speaking group TA4922, which used tax-themed lures impersonating the Indian Income Tax Department to deliver AsyncRAT via Cruciferra between late April and early June.

Separate May campaigns spoofed the US Social Security Administration to deliver XWorm, and a late-June operation used bed-bug guest-complaint lures against hospitality organizations to drop zgRAT.

Financial services accounted for 34% of observed targets, followed by healthcare at 25% and government at 10%, though Proofpoint characterized the targeting as opportunistic. The company said new Cruciferra-packed samples appeared on VirusTotal every few minutes on July 9.



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleResearchers Say Claude for Chrome Flaw Lets Rogue Extensions Trigger Gmail Reads
Next Article SAP Patches CVSS 9.9 NetWeaver ABAP Flaw That Could Expose or Modify Data
Team-CWD
  • Website

Related Posts

News

Microsoft Patches Record 622 Flaws, Including Two Zero-Days Under Active Attack

July 21, 2026
News

New HollowGraph Malware Hijacks Microsoft 365 Calendars for Covert C2

July 20, 2026
News

SAP Patches CVSS 9.9 NetWeaver ABAP Flaw That Could Expose or Modify Data

July 20, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views

Cyber M&A Roundup: Cyber Giants Strengthen AI Security Offerings

December 1, 20258 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

The WhatsApp screen-sharing scam you didn’t see coming

November 6, 2025

Why that next data breach alert could be a trap

April 18, 2026

AI-powered financial scams swamp social media

September 11, 2025

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.