Skip to content
Threat Feed
high advisory

Unpacking 'Cruciferra': Analysis of a Sophisticated Crypter Service

Cruciferra is a sophisticated crypter-as-a-service, written in Mono, actively developed and sold to multiple cybercriminal threat actors who use it to deliver a wide range of remote access trojans and infostealers, employing extensive defense evasion techniques like BYOVD-based EDR tampering, Process Ghosting, and unique cryptographic obfuscation via email-based phishing campaigns.

Proofpoint researchers are tracking "Cruciferra", a sophisticated crypter-as-a-service employed by various cybercriminal threat clusters to obfuscate and deliver a wide range of remote access trojans (RATs) and infostealers. First made available for sale in the fall of 2025 on underground forums like Exploit[.]in, Cruciferra is actively developed, with testing variants observed. Written in Mono, it incorporates numerous evasion techniques, including indirect system calls, API and IAT unhooking, Bring-Your-Own-Vulnerable-Driver (BYOVD)-based EDR tampering, privilege escalation, and a customized implementation of Process Ghosting. Its notable emphasis on payload protection involves over 90 variations of cryptographic functions, dynamically assembled, to complicate static analysis and signature-based defenses. The service is typically used in email phishing campaigns with opportunistic targeting, though financial services, healthcare, and government entities have been frequently observed as victims, delivering malware such as zgRAT, AsyncRAT, XWorm, and AgentTesla.

Attack Chain

  1. Threat actors send email phishing messages with tax-themed or guest complaint lures to victims. These emails contain either direct links or PDF attachments with embedded malicious links.
  2. Victims click the malicious links, leading to attacker-controlled landing pages that host compressed archives (ZIP or VHD files) containing malicious files like an executable and a DLL, or a malicious LNK file.
  3. The user executes the downloaded file, which triggers DLL side-loading of Cruciferra's malicious DLL, launching the crypter's code.
  4. Cruciferra executes, performing anti-analysis and defense evasion checks to detect sandboxes, virtual machines, and analysts by using numerous decoy exported functions and techniques to hide console windows.
  5. A PowerShell script or an internal Cruciferra module collects system information, performing system fingerprinting (e.g., CPU, memory, OS, network adapters, running processes, drives, services).
  6. Cruciferra performs Bring-Your-Own-Vulnerable-Driver (BYOVD) attacks, loading known vulnerable drivers (e.g., GoFlyDrv.sys, MemoryInformer.sys) to unhook APIs or tamper with EDRs, and also utilizes Process Ghosting to execute payloads covertly.
  7. Cruciferra either drops the obfuscated final payload (e.g., AsyncRAT, XWorm, zgRAT, AgentTesla) to disk or downloads it from a staging server and executes it.
  8. The final payload establishes remote access, exfiltrates sensitive information, or performs other malicious activities as per the specific malware delivered (e.g., remote access, information theft).

Impact

Cruciferra's use by multiple threat actors in opportunistic phishing campaigns has led to widespread compromises, with observed targeting across various sectors including financial services, healthcare, and government entities. The successful deployment of Cruciferra results in the installation of commodity malware like zgRAT, AgentTesla, AsyncRAT, XLoader, XWorm, Phantom Stealer, Formbook, and Remcos. Consequences for victims include remote system control, data exfiltration, and potential further exploitation or financial fraud. The crypter's sophisticated evasion techniques make detection and analysis difficult, increasing the likelihood of successful infections and prolonged dwell times for the delivered payloads.

Recommendation

  • Deploy the Sigma rule "Detect Loading of Known Vulnerable Drivers Used by Cruciferra" to your SIEM to identify BYOVD attempts leveraging specific vulnerable drivers.
  • Block the C2 domains and URLs listed in the IOC table (e.g., hxxp://hsahyteiows[.]gu[.]cc, hxxp://fuaytrwese[.]love) at the DNS resolver or proxy level.
  • Implement email filtering and security awareness training to help users identify and report phishing attempts, especially those using tax or guest complaint lures, which are common initial access vectors for Cruciferra campaigns.
  • Ensure endpoint detection and response (EDR) solutions are configured to monitor for suspicious process creation, DLL loading, and driver installations, which are indicative of Cruciferra's evasion techniques like DLL side-loading and BYOVD.
  • Configure network security tools to monitor for outbound connections to the identified payload delivery URLs and C2 infrastructure.

Detection coverage 1

Detect Loading of Known Vulnerable Drivers Used by Cruciferra

high

Detects the loading of specific vulnerable drivers identified in Cruciferra campaigns for BYOVD-based EDR tampering. These drivers are known to be abused by threat actors to gain elevated privileges and evade security solutions.

sigma tactics: defense_evasion, privilege_escalation techniques: T1068, T1562.002 sources: image_load, windows

Detection queries are available on the platform. Get full rules →

Indicators of compromise

1

domain

10

hash_sha256

TypeValue
domainexploit.in
hash_sha25617aae57cf6255c7eb169bf62ea67376d9708976eb7831f8cdd0ea38bdcb37dc4
hash_sha2562fdfdd13a0c548bb68c9d5aa8599a9265d4659da3e237fe7a42ac6ac06b9a06a
hash_sha256c4e93449453cf67c5d5605bb8f425207a738a242fdb432d720acc32faa74926c
hash_sha256c5b1e9aafc8f2b4ab05effc00fd43f3114b9ef1d592a086c952793ac4e299809
hash_sha2567887e919555fb5948c217556ba149392a72982b1bc427d3db779db9dcbf09ee8
hash_sha25609bedbf7a41e0f8dabe4f41d331db58373ce15b2e9204540873a1884f38bdde1
hash_sha2565b4f59236a9b950bcd5191b35d19125f60cfb9e1a1e1aa2e4f914b6745dde9df
hash_sha256c46e907886e2158cbc453e767183aecf07887b5ac8848f19684451883d69f5f0
hash_sha2563c181f642e24c28602a87be7f195e2f3d1ffa30b37e20f5121d99f88b22ab80e
hash_sha25666dbe675480dc229e5b3ab8ad74207f73486e64e57805074f784bb2e01bcb865