logo

Cruciferra Crypter Uses BYOVD and Process Ghosting to Hide RATs and Infostealers

ID: ffd724a4-4054-5a72-bf24-d43ac1c839ae

STIX ID: report--ffd724a4-4054-5a72-bf24-d43ac1c839ae

Feed Name: Cyber Press

Threat Score
75/100

Date Published: 2026-07-21

Date Updated: 2026-07-21

Author: Varshini

...
...

The report describes 'Cruciferra', a Mono-based commercial crypter used by multiple actors to evade detection and deploy various malware (AsyncRAT, zgRAT, Agent Tesla, Remcos, XLoader, Formbook, stealers and keyloggers). It summarizes observed phishing delivery chains (tax- and agency-themed lures), technical evasion techniques including BYOVD use of vulnerable kernel drivers and API hook removal, ties several campaigns to suspected TA4922 operations, and provides example indicators of compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.