Cruciferra Crypter Uses BYOVD and Process Ghosting to Hide RATs and Infostealers
ID: ffd724a4-4054-5a72-bf24-d43ac1c839ae
STIX ID: report--ffd724a4-4054-5a72-bf24-d43ac1c839ae
Feed Name: Cyber Press
The report describes 'Cruciferra', a Mono-based commercial crypter used by multiple actors to evade detection and deploy various malware (AsyncRAT, zgRAT, Agent Tesla, Remcos, XLoader, Formbook, stealers and keyloggers). It summarizes observed phishing delivery chains (tax- and agency-themed lures), technical evasion techniques including BYOVD use of vulnerable kernel drivers and API hook removal, ties several campaigns to suspected TA4922 operations, and provides example indicators of compromise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
