logo

Cruciferra Crypter Uses Process Ghosting to Evade Detection

ID: 22174e5f-0e5a-5f43-ae50-c77f1a7f4098

STIX ID: report--22174e5f-0e5a-5f43-ae50-c77f1a7f4098

Feed Name: Infosecurity Magazine (News)

Threat Score
78/100

Date Published: 2026-07-20

Date Updated: 2026-07-20

...
...

Proofpoint research documents a commercial crypter called 'Cruciferra' used by multiple criminal operators to deliver RATs and keyloggers via DLL side‑loading; the crypter employs advanced techniques — custom mix‑and‑match cryptographic routines, BYOVD kernel driver abuse to disable EDR, and a hardened form of process ghosting — and has been linked to active campaigns (including TA4922) targeting financial, healthcare and government organizations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.