New Crypter-as-a-Service Cruciferra Fuels Stealthy Malware Attacks Worldwide
New Crypter-as-a-Service Cruciferra Fuels Stealthy Malware Attacks Worldwide 🚀
Proofpoint has uncovered Cruciferra, a crypter-as-a-service that assists hackers in evading antivirus systems and delivering malware through various campaigns. Their research team traced a wave of income-tax-themed lures back to this crypter service, which is utilized by multiple unrelated criminal groups.
A crypter’s primary function is to scramble a malicious payload so that antivirus tools cannot detect it, then unwrap it at the right moment on the victim’s machine. Cruciferra is designed to be stealthy, employing indirect system calls, API unhooking, and a custom version of Process Ghosting to leave minimal traces for forensic investigators.
The report highlights that Cruciferra features numerous techniques aimed at evading detection, including:
- Indirect system calls
- API and Import Address Table (IAT) unhooking
- Bring-Your-Own-Vulnerable-Driver (BYOVD)-based EDR tampering
- Privilege escalation
- Persistence mechanisms
- Customized Process Ghosting implementation
Cruciferra supports a wide array of custom encryption routines, complicating static analysis and signature-based defenses. Sellers have been advertising it on underground forums since fall 2025, with prices ranging from $450 to $2,000 per month, protecting various malware types such as Agent Tesla, AsyncRAT, Remcos RAT, Snake Keylogger, and XWorm.
What makes Cruciferra particularly challenging to fingerprint is its use of multiple encryption methods. Each batch of samples employs a unique encryption routine, crafted by mixing components from established cryptographic algorithms. One campaign linked to Cruciferra involved a Chinese-speaking group, TA4922, which directed victims to fake landing pages hosting ZIP files disguised as tax documents in several waves between April and early June 2026.
Cruciferra has also been seen in unrelated campaigns, impersonating the US Social Security Administration in May to deliver XWorm and AdaptixC2, and targeting hotels with zgRAT malware using bed bug complaints in late June. The deployment method always involves DLL side-loading and employs evasion tricks, including exploiting a vulnerable driver called GoFlyDrv.sys to terminate security processes. Notably, the final payload never exists as a real file on disk; Cruciferra runs code from a temporary file that is deleted before the process starts.
While the individual techniques are not new, the combination of them in one modular package is what sets Cruciferra apart. The report concludes that while crypters have long been used to evade detection, Cruciferra distinguishes itself through its extensive and unique defense-evasion capabilities, modular design, and highly customized approach to payload protection.
Researchers have observed Cruciferra delivering numerous malware families, including various remote access trojans and infostealers, emphasizing its role as a crucial technology within the cybercrime ecosystem.