discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.
Featured

Cruciferra Crypter Uses BYOVD and Process Ghosting to Hide Windows Malware

A China-linked cybercrime group has been observed using a sophisticated crypter service called Cruciferra to deliver a wide array of remote access trojans (RATs) and information stealer malware.

By Ravie Lakshmanan·Jul 27·thehackernews.com·2 min read

Intelligence analysis by Llama

Cruciferra Crypter Uses BYOVD and Process Ghosting to Hide Windows Malware
Image: thehackernews.com

Cruciferra is a crypter service used by various cybercriminal threat clusters to deliver malware, featuring techniques to evade detection, analysis, and incident response efforts.

Why it matters

The use of Cruciferra highlights the sophistication and adaptability of cybercriminals in evading detection and delivering malware, posing a significant threat to organizations and individuals.

Imagine a super-sophisticated tool that helps bad guys hide their malware from security software. This tool, called Cruciferra, is like a magic cloak that makes it hard for security experts to detect and stop the malware. It's like a game of cat and mouse, where the bad guys keep updating their tool to stay one step ahead of the security experts.

Analysis

A Sophisticated Crypter Service

Cruciferra is a sophisticated crypter service used by various cybercriminal threat clusters to deliver a wide array of remote access trojans (RATs) and information stealer malware. The service has been advertised on the cybercrime underground as the 'most lethal crypter' for $450 to $2,000 a month.

Evasion Techniques

Cruciferra features numerous techniques designed to evade detection, analysis, and incident response efforts. These include using indirect system calls, API and Import Address Table (IAT) unhooking, bring-your-own-vulnerable-driver (BYOVD)-based EDR tampering, privilege escalation, persistence mechanisms, and a customized implementation of Process Ghosting used to execute payloads while minimizing forensic artifacts.

Payload Protection

An emphasis on payload protection notwithstanding, Cruciferra supports various custom encryption routines that appear to be dynamically derived and assembled from established cryptographic algorithms, thereby introducing variations between samples and complicating static analysis as well as signature-based detections. The algorithm used to encrypt payloads and strings in each set of samples is different, and there is such a large variance of these algorithms, which means it is probably randomly generated (polymorphically) from elements of well-known hashing, PRNG, and cipher algorithms.

Campaigns and Targets

The activity is assessed to be opportunistic, reaching anywhere between hundreds and thousands of messages per campaign. The primary targets include financial services, healthcare, government, education, and manufacturing sectors. One such campaign has been attributed to Chinese-speaking cybercrime actor TA4922, which shares some level of overlap with another prolific threat group called Silver Fox.

Key points

  • Cruciferra is a sophisticated crypter service used by various cybercriminal threat clusters to deliver malware.
  • The service features numerous techniques designed to evade detection, analysis, and incident response efforts.
  • Cruciferra supports various custom encryption routines that appear to be dynamically derived and assembled from established cryptographic algorithms.
  • The activity is assessed to be opportunistic, reaching anywhere between hundreds and thousands of messages per campaign.
  • The primary targets include financial services, healthcare, government, education, and manufacturing sectors.
The Upside

If the development of Cruciferra is addressed, it could lead to a decrease in the number of successful malware attacks, as security experts would have a better chance of detecting and stopping the malware. Additionally, the use of custom encryption routines could lead to a decrease in the number of malware variants, making it easier for security experts to develop effective detection and prevention strategies.

The Downside

If the development of Cruciferra continues, it could lead to a significant increase in the number of successful malware attacks, as the bad guys would have a sophisticated tool to help them evade detection. This could also lead to a decrease in the effectiveness of security software, making it harder for security experts to detect and stop the malware.

Originally reported at

thehackernews.com

Discernion covers the story. Read the full piece at the source.

Tagscybercrimeemail securityendpoint securityinformation stealermalwarephishingremote access trojanthreat intelligencewindows security

Author

Ravie Lakshmanan

Intelligence analysis by

Llama

Published

Jul 27, 2026

Source

thehackernews.com

Share

Topics

cybercrimeemail securityendpoint securityinformation stealermalwarephishingremote access trojanthreat intelligencewindows security

Related

More from this desk

Jul 27·bleepingcomputer.com

Apple sued over fake App Store crypto wallet app stealing $1.8M in Bitcoin

Apple is being sued by three people who claim approximately $1.8 million in Bitcoin was stolen after downloading and using a fraudulent Sparrow Wallet application from the App Store.

Jul 27·thehackernews.com

Dysphoria IoT Botnet Adds Blockchain C2 and Victim Relays After JackSkid Disruption

The Dysphoria IoT botnet has adopted blockchain-based name services and infected-device relays after a March law-enforcement operation against JackSkid infrastructure. The botnet's population is estimated to be above 200,000 bots, with 4,401 confirmed active devices insid…

Jul 27·bleepingcomputer.com

Coca-Cola Confirms Data Theft in Fairlife Ransomware Attack

Coca-Cola has confirmed that hackers stole data from its dairy subsidiary, Fairlife, during a ransomware attack earlier this month. The company says it is still working to restore some of the impacted systems and operations, but most of the production in the U.S. has been…

Jul 27·bleepingcomputer.com

Ernst & Young data breach claimed by ShinyHunters extortion gang

The ShinyHunters extortion gang has claimed responsibility for a recently disclosed Ernst & Young data breach, saying it obtained credentials for some of the company's systems via a supply-chain attack.