Cruciferra Crypter Uses BYOVD and Process Ghosting to Hide Windows Malware
A China-linked cybercrime group has been observed using a sophisticated crypter service called Cruciferra to deliver a wide array of remote access trojans (RATs) and information stealer malware.
Intelligence analysis by Llama

Cruciferra is a crypter service used by various cybercriminal threat clusters to deliver malware, featuring techniques to evade detection, analysis, and incident response efforts.
Imagine a super-sophisticated tool that helps bad guys hide their malware from security software. This tool, called Cruciferra, is like a magic cloak that makes it hard for security experts to detect and stop the malware. It's like a game of cat and mouse, where the bad guys keep updating their tool to stay one step ahead of the security experts.
Analysis
A Sophisticated Crypter Service
Cruciferra is a sophisticated crypter service used by various cybercriminal threat clusters to deliver a wide array of remote access trojans (RATs) and information stealer malware. The service has been advertised on the cybercrime underground as the 'most lethal crypter' for $450 to $2,000 a month.
Evasion Techniques
Cruciferra features numerous techniques designed to evade detection, analysis, and incident response efforts. These include using indirect system calls, API and Import Address Table (IAT) unhooking, bring-your-own-vulnerable-driver (BYOVD)-based EDR tampering, privilege escalation, persistence mechanisms, and a customized implementation of Process Ghosting used to execute payloads while minimizing forensic artifacts.
Payload Protection
An emphasis on payload protection notwithstanding, Cruciferra supports various custom encryption routines that appear to be dynamically derived and assembled from established cryptographic algorithms, thereby introducing variations between samples and complicating static analysis as well as signature-based detections. The algorithm used to encrypt payloads and strings in each set of samples is different, and there is such a large variance of these algorithms, which means it is probably randomly generated (polymorphically) from elements of well-known hashing, PRNG, and cipher algorithms.
Campaigns and Targets
The activity is assessed to be opportunistic, reaching anywhere between hundreds and thousands of messages per campaign. The primary targets include financial services, healthcare, government, education, and manufacturing sectors. One such campaign has been attributed to Chinese-speaking cybercrime actor TA4922, which shares some level of overlap with another prolific threat group called Silver Fox.
Key points
- Cruciferra is a sophisticated crypter service used by various cybercriminal threat clusters to deliver malware.
- The service features numerous techniques designed to evade detection, analysis, and incident response efforts.
- Cruciferra supports various custom encryption routines that appear to be dynamically derived and assembled from established cryptographic algorithms.
- The activity is assessed to be opportunistic, reaching anywhere between hundreds and thousands of messages per campaign.
- The primary targets include financial services, healthcare, government, education, and manufacturing sectors.
If the development of Cruciferra is addressed, it could lead to a decrease in the number of successful malware attacks, as security experts would have a better chance of detecting and stopping the malware. Additionally, the use of custom encryption routines could lead to a decrease in the number of malware variants, making it easier for security experts to develop effective detection and prevention strategies.
If the development of Cruciferra continues, it could lead to a significant increase in the number of successful malware attacks, as the bad guys would have a sophisticated tool to help them evade detection. This could also lead to a decrease in the effectiveness of security software, making it harder for security experts to detect and stop the malware.



