Cruciferra Crypter Uses BYOVD and Process Ghosting to Hide RATs and Infostealers

The tool combines payload encryption with advanced Windows evasion methods, helping attackers bypass endpoint defenses and complicate incident response.

Cruciferra is a Mono-based crypter marketed on underground forums as a high-end service for malware operators. First advertised in late 202520252025, subscriptions reportedly range from $450\$450$450 to $2,000\$2{,}000$2,000 per month depending on features.

Crypters wrap malicious files in layers of obfuscation and encryption so security tools cannot easily inspect or identify the final payload.

Proofpoint observed Cruciferra protecting a broad range of malware, including AsyncRAT, zgRAT, Agent Tesla, Remcos, XWorm, XLoader, Formbook, Phantom Stealer, DarkCloud Stealer, and Snake Keylogger.

Cruciferra Crypter Evades Detection

The service appears to be an umbrella label for multiple related crypter builds. Researchers found production samples as well as apparent test versions containing debugging code and experimental features.

Its large feature set makes it useful to many actors rather than a single threat group.

Observed campaigns commonly begin with phishing emails carrying links to ZIP archives, virtual hard disk files, or fake document portals.

A public advertisement and notice of Cruciferra (Source: proofpoint)
A public advertisement and notice of Cruciferra (Source: proofpoint)

The archives often include a legitimate executable and a malicious DLL. When the victim launches the executable, it side-loads the DLL containing Cruciferra code.

Proofpoint linked four campaigns between late April and early June 202620262026 to TA4922, a suspected Chinese-speaking cybercrime group.

Those operations used tax-themed emails impersonating India’s Income Tax Department or government agencies. Victims were sent to fake tax portals and prompted to download files that ultimately installed Cruciferra and AsyncRAT.

Other activity included emails impersonating the U.S. Social Security Administration to deliver XWorm and AdaptixC2.

A late-June campaign targeting hospitality and travel organizations used guest-complaint and bed-bug lures. That infection chain collected system information before downloading Cruciferra, which then deployed zgRAT.

Cruciferra performs extensive checks before releasing its final payload. It includes fake exported DLL functions that lead analysts and automated sandboxes toward harmless junk code.

It can also hide console windows associated with its processes, reducing visual clues that may alert victims. The crypter attempts to remove monitoring hooks from Windows APIs, including hooks in the Import Address Table.

Fake Income Tax Department portal used to host the ZIP file which initiates the Cruciferra infection chain (Source: proofpoint)
Fake Income Tax Department portal used to host the ZIP file which initiates the Cruciferra infection chain (Source: proofpoint)

These hooks are often used by endpoint detection and response products, antivirus engines, and sandboxes to observe suspicious program behavior.

A key capability is its use of Bring-Your-Own-Vulnerable-Driver, or BYOVD. Cruciferra can drop legitimate but vulnerable kernel drivers, including GoFlyDrv.sys, then abuse their low-level access to identify and terminate security processes.

Other observed helper drivers include Core64.sys, HwOs2Ec.sys, LnvMSRIO.MemoryInformer.sys, and NTIOLib_X64.sys, Proofpoint said.

Indicators of Compromise

IndicatorTypeDescriptionFirst Seen
hxxp://hsahyteiows[.]gu[.]ccURLTA4922 Cruciferra / AsyncRAT payload28 April 2026
hxxp://yicoweytcbtw[.]gu[.]ccURLTA4922 Cruciferra / Asyn

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Prevent critical incidents and financial loss with stronger proactive defense. Integrate a live threat feed from 15K SOCs

Varshini
Varshini
Varshini is a Cyber Security expert in Threat Analysis, Vulnerability Assessment, and Research. Passionate about staying ahead of emerging Threats and Technologies..

Trending News

Related Stories