logo

This $2,000-a-Month Crypter Can Kill EDR and Make Malware Disappear From Disk

ID: c88d89ba-7e43-5e52-b9f0-0d013b3a7580

STIX ID: report--c88d89ba-7e43-5e52-b9f0-0d013b3a7580

Feed Name: cybersecurityNews.com

Threat Score
80/100

Date Published: 2026-07-21

Date Updated: 2026-07-21

Author: Tushar Subhra Dutta

...
...

Proofpoint identified a commercial crypter called “Cruciferra” (sold by subscription) that has been used since late 2025 to wrap and deliver multiple RATs and information-stealers (AsyncRAT, XWorm, zgRAT, Agent Tesla, Formbook, Remcos, XLoader) via DLL side‑loading, process ghosting, and BYOVD attacks using signed vulnerable drivers; campaigns used tax, SSA, and complaint-themed lures across email, PDFs, ZIPs and other artifacts, targeting financial, healthcare, government, travel, and hospitality sectors and including numerous IoCs (URLs, file hashes, drivers).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.