logo

Hackers Use Cruciferra Crypter to Disable EDR and Deploy XWorm, Remcos, and AsyncRAT

ID: d97e950a-45ca-5448-b666-9a04f2d26ba6

STIX ID: report--d97e950a-45ca-5448-b666-9a04f2d26ba6

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2026-07-21

Date Updated: 2026-07-21

Author: Mayura Kathir

...
...

Proofpoint analyzed Cruciferra, a Mono-based crypter-as-a-service actively used in global email campaigns to turn off EDR/endpoint protections and stealthily deploy RATs and stealers (AsyncRAT, XWorm, Remcos, Agent Tesla, etc.). The service employs layered defense-evasion (user-/kernel-mode unhooking, BYOVD vulnerable-driver abuse, indirect syscalls, polymorphic encryption with >90 routines) and flexible delivery (side-loaded DLLs, VHD/ZIP containers, staged downloads). Multiple crime clusters and TA4922 campaigns used tax, SSA, and hospitality lures to distribute Cruciferra-backed payloads across financial, healthcare, government, and travel sectors; the report includes numerous defanged IOCs and behavioral details for detection and tracking.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.