This $2,000-a-Month Crypter Can Kill EDR and Make Malware Disappear From Disk
ID: c88d89ba-7e43-5e52-b9f0-0d013b3a7580
STIX ID: report--c88d89ba-7e43-5e52-b9f0-0d013b3a7580
Feed Name: cybersecurityNews.com
Proofpoint identified a commercial crypter called “Cruciferra” (sold by subscription) that has been used since late 2025 to wrap and deliver multiple RATs and information-stealers (AsyncRAT, XWorm, zgRAT, Agent Tesla, Formbook, Remcos, XLoader) via DLL side‑loading, process ghosting, and BYOVD attacks using signed vulnerable drivers; campaigns used tax, SSA, and complaint-themed lures across email, PDFs, ZIPs and other artifacts, targeting financial, healthcare, government, travel, and hospitality sectors and including numerous IoCs (URLs, file hashes, drivers).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
