Cruciferra Crypter Uses Process Ghosting to Evade Detection
ID: 22174e5f-0e5a-5f43-ae50-c77f1a7f4098
STIX ID: report--22174e5f-0e5a-5f43-ae50-c77f1a7f4098
Feed Name: Infosecurity Magazine (News)
Threat Score
Proofpoint research documents a commercial crypter called 'Cruciferra' used by multiple criminal operators to deliver RATs and keyloggers via DLL side‑loading; the crypter employs advanced techniques — custom mix‑and‑match cryptographic routines, BYOVD kernel driver abuse to disable EDR, and a hardened form of process ghosting — and has been linked to active campaigns (including TA4922) targeting financial, healthcare and government organizations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
