Proofpoint
Cruciferra Crypter Service Powers Multiple Cybercrime Campaigns
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Proofpoint has identified a sophisticated crypter service named Cruciferra, first sold in autumn 2025, that is utilized by various cybercriminal groups to cloak malware. The service employs advanced techniques such as process ghosting, kernel-driver abuse, and over 90 encryption routines to evade detection. Campaigns leveraging Cruciferra have delivered malware like AsyncRAT, AgentTesla, and XWorm, targeting sectors including financial services. The crypter is marketed on dark web forums, claiming to be 'the underground's most lethal crypter,' with tiered pricing from $450 to $2,000 per month. Proofpoint's research indicates that both production and testing samples of Cruciferra are actively being developed. The malware is delivered through methods like DLL side-loading, where a legitimate executable is paired with a malicious DLL. This DLL inspects the environment before dropping the payload, complicating detection efforts. The campaigns have been observed to have opportunistic targeting, with message volumes ranging from hundreds to thousands per campaign.
Key Points: • Cruciferra is a crypter service used by multiple cybercriminal groups since late 2025. • It employs advanced evasion techniques including process ghosting and kernel-driver abuse. • Proofpoint observed campaigns delivering various malware types, impacting sectors like financial services.