{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/tags/crypter/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":[],"_cs_severities":["high"],"_cs_tags":["crypter","malware-as-a-service","defense-evasion","remote-access-trojan","infostealer","windows"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eProofpoint researchers are tracking \u0026quot;Cruciferra\u0026quot;, a sophisticated crypter-as-a-service employed by various cybercriminal threat clusters to obfuscate and deliver a wide range of remote access trojans (RATs) and infostealers. First made available for sale in the fall of 2025 on underground forums like Exploit[.]in, Cruciferra is actively developed, with testing variants observed. Written in Mono, it incorporates numerous evasion techniques, including indirect system calls, API and IAT unhooking, Bring-Your-Own-Vulnerable-Driver (BYOVD)-based EDR tampering, privilege escalation, and a customized implementation of Process Ghosting. Its notable emphasis on payload protection involves over 90 variations of cryptographic functions, dynamically assembled, to complicate static analysis and signature-based defenses. The service is typically used in email phishing campaigns with opportunistic targeting, though financial services, healthcare, and government entities have been frequently observed as victims, delivering malware such as zgRAT, AsyncRAT, XWorm, and AgentTesla.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eThreat actors send email phishing messages with tax-themed or guest complaint lures to victims. These emails contain either direct links or PDF attachments with embedded malicious links.\u003c/li\u003e\n\u003cli\u003eVictims click the malicious links, leading to attacker-controlled landing pages that host compressed archives (ZIP or VHD files) containing malicious files like an executable and a DLL, or a malicious LNK file.\u003c/li\u003e\n\u003cli\u003eThe user executes the downloaded file, which triggers DLL side-loading of Cruciferra's malicious DLL, launching the crypter's code.\u003c/li\u003e\n\u003cli\u003eCruciferra executes, performing anti-analysis and defense evasion checks to detect sandboxes, virtual machines, and analysts by using numerous decoy exported functions and techniques to hide console windows.\u003c/li\u003e\n\u003cli\u003eA PowerShell script or an internal Cruciferra module collects system information, performing system fingerprinting (e.g., CPU, memory, OS, network adapters, running processes, drives, services).\u003c/li\u003e\n\u003cli\u003eCruciferra performs Bring-Your-Own-Vulnerable-Driver (BYOVD) attacks, loading known vulnerable drivers (e.g., \u003ccode\u003eGoFlyDrv.sys\u003c/code\u003e, \u003ccode\u003eMemoryInformer.sys\u003c/code\u003e) to unhook APIs or tamper with EDRs, and also utilizes Process Ghosting to execute payloads covertly.\u003c/li\u003e\n\u003cli\u003eCruciferra either drops the obfuscated final payload (e.g., AsyncRAT, XWorm, zgRAT, AgentTesla) to disk or downloads it from a staging server and executes it.\u003c/li\u003e\n\u003cli\u003eThe final payload establishes remote access, exfiltrates sensitive information, or performs other malicious activities as per the specific malware delivered (e.g., remote access, information theft).\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eCruciferra's use by multiple threat actors in opportunistic phishing campaigns has led to widespread compromises, with observed targeting across various sectors including financial services, healthcare, and government entities. The successful deployment of Cruciferra results in the installation of commodity malware like zgRAT, AgentTesla, AsyncRAT, XLoader, XWorm, Phantom Stealer, Formbook, and Remcos. Consequences for victims include remote system control, data exfiltration, and potential further exploitation or financial fraud. The crypter's sophisticated evasion techniques make detection and analysis difficult, increasing the likelihood of successful infections and prolonged dwell times for the delivered payloads.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDeploy the Sigma rule \u0026quot;Detect Loading of Known Vulnerable Drivers Used by Cruciferra\u0026quot; to your SIEM to identify BYOVD attempts leveraging specific vulnerable drivers.\u003c/li\u003e\n\u003cli\u003eBlock the C2 domains and URLs listed in the IOC table (e.g., \u003ccode\u003ehxxp://hsahyteiows[.]gu[.]cc\u003c/code\u003e, \u003ccode\u003ehxxp://fuaytrwese[.]love\u003c/code\u003e) at the DNS resolver or proxy level.\u003c/li\u003e\n\u003cli\u003eImplement email filtering and security awareness training to help users identify and report phishing attempts, especially those using tax or guest complaint lures, which are common initial access vectors for Cruciferra campaigns.\u003c/li\u003e\n\u003cli\u003eEnsure endpoint detection and response (EDR) solutions are configured to monitor for suspicious process creation, DLL loading, and driver installations, which are indicative of Cruciferra's evasion techniques like DLL side-loading and BYOVD.\u003c/li\u003e\n\u003cli\u003eConfigure network security tools to monitor for outbound connections to the identified payload delivery URLs and C2 infrastructure.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-20T09:04:43Z","date_published":"2026-07-20T09:04:43Z","id":"https://feed.craftedsignal.io/briefs/2026-07-cruciferra-crypter-service/","summary":"Cruciferra is a sophisticated crypter-as-a-service, written in Mono, actively developed and sold to multiple cybercriminal threat actors who use it to deliver a wide range of remote access trojans and infostealers, employing extensive defense evasion techniques like BYOVD-based EDR tampering, Process Ghosting, and unique cryptographic obfuscation via email-based phishing campaigns.","title":"Unpacking 'Cruciferra': Analysis of a Sophisticated Crypter Service","url":"https://feed.craftedsignal.io/briefs/2026-07-cruciferra-crypter-service/"}],"language":"en","title":"CraftedSignal Threat Feed - Crypter","version":"https://jsonfeed.org/version/1.1"}