Close Menu
    What's Hot

    Trump Gutted the Kennedy Center. A Tour Guide Wants You to See It Anyway.

    New Heat Wave Could Intensify Wildfires in France and Spain

    The A.I. Debate That’s Driving a Wedge Through Big Tech

    Facebook X (Twitter) Instagram
    Trending
    • Trump Gutted the Kennedy Center. A Tour Guide Wants You to See It Anyway.
    • New Heat Wave Could Intensify Wildfires in France and Spain
    • The A.I. Debate That’s Driving a Wedge Through Big Tech
    • Cruciferra Crypter Uses BYOVD and Process Ghosting to Hide Windows Malware
    • A Top-Rated Travel Pillow Just Got Even Better: Our Review
    • Mideast Economic Integration Holds Few Benefits for the U.S.
    • Jeffries Kicks Off Midterm Sprint With Economic Pitch
    • 15 Sailors Still Missing After Vietnamese Cargo Ship Sank in South China Sea
    interluknewsinterluknews
    • Home
    • Business
      • Corporate News
      • Industry Insights
      • Startups & Entrepreneurship
      • Technology & Innovation
    • Economy
      • Economic Policy
      • Financial Analysis
      • Inflation & Interest Rates
      • Trade & Markets
    • Global
      • Conflicts & Security
      • Diplomacy
      • Global Trends
      • International Affairs
    • Lifestyle
      • Fashion
      • Food & Dining
      • Personal Development
      • Travel
    • Opinion
      • Columns
      • Editorials
      • Expert Opinions
      • Reader Voices
    • More
      • Politics
        • Elections
        • Government & Policy
        • International Relations
        • Political Analysis
      • Sports
        • Cricket
        • Football / Soccer
        • International Sports
        • Local Sports
      • Technology
        • Artificial Intelligence
        • Cybersecurity
        • Gadgets & Reviews
        • Tech News
      • South Africa News
    Facebook X (Twitter) Instagram
    interluknewsinterluknews
    Cybersecurity

    Cruciferra Crypter Uses BYOVD and Process Ghosting to Hide Windows Malware

    adminBy adminJuly 27, 2026No Comments4 Mins Read
    Share Facebook Twitter Pinterest Copy Link Telegram LinkedIn Tumblr Email
    Cruciferra Crypter Uses BYOVD and Process Ghosting to Hide Windows Malware
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Cruciferra Crypter Uses BYOVD and Process Ghosting to Hide Windows Malware

    The China-linked cybercrime group behind the use of income tax-related phishing lures targeting Indian taxpayers, tax professionals, and corporate finance teams has been observed using a sophisticated crypter service called Cruciferra.

    According to a new analysis by Proofpoint, Cruciferra has been utilized by various unrelated cybercriminal threat clusters to deliver a wide array of remote access trojans (RATs) and information stealer malware.

    “Cruciferra is written in Mono and features numerous techniques designed to evade detection, analysis, and incident response efforts,” the enterprise security company said in an analysis published last week.

    “These include using indirect system calls, API and Import Address Table (IAT) unhooking, bring-your-own-vulnerable-driver (BYOVD)-based EDR tampering, privilege escalation, persistence mechanisms, and a customized implementation of Process Ghosting used to execute payloads while minimizing forensic artifacts.”

    Crypters (also spelled cryptors) play an important role in the cybercriminal ecosystem as they allow bad actors to obfuscate their payloads, avoid detection, and improve malware delivery success rates.

    An emphasis on payload protection notwithstanding, Cruciferra supports various custom encryption routines that appear to be dynamically derived and assembled from established cryptographic algorithms, thereby introducing variations between samples and complicating static analysis as well as signature-based detections.

    Cybersecurity

    “The algorithm used to encrypt payloads and strings in each set of samples is different, and there is such a large variance of these algorithms, which means it is probably randomly generated (polymorphically) from elements of well-known hashing, PRNG, and cipher algorithms,” per researchers Chris Wakelin, Georgi Mladenov, and Kyle Cucci.

    The service has been advertised on the cybercrime underground as the “most lethal crypter” for $450 to $2,000 a month. It was first made available for sale in fall 2025. Some of the commodity malware families distributed via Cruciferra include Agent Tesla, AsyncRAT, DarkCloud Stealer, Formbook, Phantom Stealer, Remcos RAT, Snake Keylogger, ValleyRAT, XLoader, XWorm, and zgRAT.

    Campaigns leveraging the crypter have leveraged phishing as the primary initial access vector, with the tool incorporating the flexibility to either drop an encrypted payload to disk or download it from a staging server. The activity is assessed to be opportunistic, reaching anywhere between hundreds and thousands of messages per campaign. The primary targets include financial services, healthcare, government, education, and manufacturing sectors.

    One such campaign has been attributed to Chinese-speaking cybercrime actor TA4922, which shares some level of overlap with another prolific threat group called Silver Fox. This involves employing tax-themed lures to drive victims to attacker-controlled landing pages hosting ZIP files to deliver malware. Four such campaigns have been identified between April and early June 2026.

    It’s worth mentioning here that this attack was documented in detail earlier this month by Seqrite Labs and Cyderes Howler Cell. Seqrite Labs is tracking the activity under the moniker Operation DragonReturn.

    Other campaigns that have been observed using Cruciferra are below –

    • Emails impersonating the U.S. Social Security Administration (SSA) to deliver XWorm and AdaptixC2 (May 2026)
    • Email using themes related to bed bugs and guest complaints to target organizations in the hospitality and travel industries and deliver zgRAT (late June 2026)

    Regardless of the campaign, Cruciferra is always executed via DLL side-loading, while leveraging evasion and anti-analysis techniques to fly under the radar. This includes hiding console windows, unhooking Windows API functions to reduce visibility, indirect system calls, disabling user notifications, and the abuse of the “GoFlyDrv.sys” driver as part of a BYOVD attack to terminate security processes.

    Cybersecurity

    “Cruciferra checks if it is running with Administrator privileges, and if not, attempts to elevate its privileges by bypassing UAC using the COM Elevation Moniker,” Proofpoint explained. “Additionally, Cruciferra establishes persistence by writing to the registry Software\Microsoft\Windows\CurrentVersion\Run key with a default value of ‘putty.’ This ensures Cruciferra runs after system reboot.”

    The final payload is loaded into memory using a variant of Process Ghosting, which, at a high level, refers to an advanced malware evasion technique on Windows where malicious code is executed from a temporary file that is deleted from the disk before the process starts. This, in turn, blinds security products as there is no “file” to scan.

    Cruciferra adds an extra layer of sophistication by patching ZwQueryVirtualMemory hooks and by attempting to tamper with the NtManageHotPatch routine to hide the deletion of the file and neutralize integrity checks.

    “While crypters have long been used to evade detection and increase malware delivery and execution success rates, Cruciferra distinguishes itself through its extensive and unique defense-evasion capabilities, modular design, and highly customized and varied approach to payload protection,” Proofpoint concluded.

    BYOVD Cruciferra Crypter Ghosting Hide Malware process Windows
    Follow on Google News Follow on Flipboard
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
    Previous ArticleA Top-Rated Travel Pillow Just Got Even Better: Our Review
    Next Article The A.I. Debate That’s Driving a Wedge Through Big Tech
    admin
    • Website

    Related Posts

    TELESHIM Abuses Telegram for C2 in Attacks Against Middle East Governments

    July 27, 2026

    Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable

    July 25, 2026

    DevMan RaaS Portal Centralizes Payload Builds, Victim Management, and Affiliate Payouts

    July 25, 2026
    Leave A Reply Cancel Reply

    Demo
    Latest Posts

    Trump Gutted the Kennedy Center. A Tour Guide Wants You to See It Anyway.

    New Heat Wave Could Intensify Wildfires in France and Spain

    The A.I. Debate That’s Driving a Wedge Through Big Tech

    Cruciferra Crypter Uses BYOVD and Process Ghosting to Hide Windows Malware

    Latest Posts

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    Advertisement
    Demo

    We are a digital news platform delivering timely, accurate, and insightful coverage of politics, global affairs, business, economy, sports, and more. Our mission is to keep readers informed with reliable news, clear analysis, and stories that truly matter.
    We're social. Connect with us:

    Facebook X (Twitter) Instagram Pinterest YouTube

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.

    Powered by
    ...
    ►
    Necessary cookies enable essential site features like secure log-ins and consent preference adjustments. They do not store personal data.
    None
    ►
    Functional cookies support features like content sharing on social media, collecting feedback, and enabling third-party tools.
    None
    ►
    Analytical cookies track visitor interactions, providing insights on metrics like visitor count, bounce rate, and traffic sources.
    None
    ►
    Advertisement cookies deliver personalized ads based on your previous visits and analyze the effectiveness of ad campaigns.
    None
    ►
    Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
    None
    Powered by