logo

Cruciferra Crypter Uses BYOVD and Process Ghosting to Hide Windows Malware

ID: 7b56af21-9b2b-574b-be9f-516fc49d6111

STIX ID: report--7b56af21-9b2b-574b-be9f-516fc49d6111

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2026-07-27

Date Updated: 2026-07-27

Author: [email protected] (The Hacker News)

...
...

Proofpoint analysis describes Cruciferra, a sophisticated Mono-based crypter sold on criminal forums and used by multiple China-linked cybercrime clusters to obfuscate and deliver RATs and information stealers (e.g., Agent Tesla, AsyncRAT, XLoader) via phishing campaigns targeting finance, healthcare, government, education, and manufacturing. The service employs DLL side-loading, polymorphic payload encryption, BYOVD driver abuse (GoFlyDrv.sys), UAC bypass via the COM Elevation Moniker, persistence via the Run registry key ('putty'), and a customized Process Ghosting implementation to minimize forensic artifacts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.