The tool combines payload encryption with advanced Windows evasion methods, helping attackers bypass endpoint defenses and complicate incident response.
Cruciferra is a Mono-based crypter marketed on underground forums as a high-end service for malware operators. First advertised in late 202520252025, subscriptions reportedly range from $450\$450$450 to $2,000\$2{,}000$2,000 per month depending on features.
Crypters wrap malicious files in layers of obfuscation and encryption so security tools cannot easily inspect or identify the final payload.
Proofpoint observed Cruciferra protecting a broad range of malware, including AsyncRAT, zgRAT, Agent Tesla, Remcos, XWorm, XLoader, Formbook, Phantom Stealer, DarkCloud Stealer, and Snake Keylogger.
Cruciferra Crypter Evades Detection
The service appears to be an umbrella label for multiple related crypter builds. Researchers found production samples as well as apparent test versions containing debugging code and experimental features.
Its large feature set makes it useful to many actors rather than a single threat group.
Observed campaigns commonly begin with phishing emails carrying links to ZIP archives, virtual hard disk files, or fake document portals.

The archives often include a legitimate executable and a malicious DLL. When the victim launches the executable, it side-loads the DLL containing Cruciferra code.
Proofpoint linked four campaigns between late April and early June 202620262026 to TA4922, a suspected Chinese-speaking cybercrime group.
Those operations used tax-themed emails impersonating India’s Income Tax Department or government agencies. Victims were sent to fake tax portals and prompted to download files that ultimately installed Cruciferra and AsyncRAT.
Other activity included emails impersonating the U.S. Social Security Administration to deliver XWorm and AdaptixC2.
A late-June campaign targeting hospitality and travel organizations used guest-complaint and bed-bug lures. That infection chain collected system information before downloading Cruciferra, which then deployed zgRAT.
Cruciferra performs extensive checks before releasing its final payload. It includes fake exported DLL functions that lead analysts and automated sandboxes toward harmless junk code.
It can also hide console windows associated with its processes, reducing visual clues that may alert victims. The crypter attempts to remove monitoring hooks from Windows APIs, including hooks in the Import Address Table.

These hooks are often used by endpoint detection and response products, antivirus engines, and sandboxes to observe suspicious program behavior.
A key capability is its use of Bring-Your-Own-Vulnerable-Driver, or BYOVD. Cruciferra can drop legitimate but vulnerable kernel drivers, including GoFlyDrv.sys, then abuse their low-level access to identify and terminate security processes.
Other observed helper drivers include Core64.sys, HwOs2Ec.sys, LnvMSRIO.MemoryInformer.sys, and NTIOLib_X64.sys, Proofpoint said.
Indicators of Compromise
| Indicator | Type | Description | First Seen |
|---|---|---|---|
hxxp://hsahyteiows[.]gu[.]cc | URL | TA4922 Cruciferra / AsyncRAT payload | 28 April 2026 |
hxxp://yicoweytcbtw[.]gu[.]cc | URL | TA4922 Cruciferra / Asyn |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Prevent critical incidents and financial loss with stronger proactive defense. Integrate a live threat feed from 15K SOCs