Proofpoint
Cruciferra Crypter Service Powers Multiple Cybercrime Campaigns
Article Content
Proofpoint has identified a sophisticated crypter service named Cruciferra, first sold in autumn 2025, that is utilized by various cybercriminal groups to cloak malware. The service employs advanced techniques such as process ghosting, kernel-driver abuse, and over 90 encryption routines to evade detection. Campaigns leveraging Cruciferra have delivered malware like AsyncRAT, AgentTesla, and XWorm, targeting sectors including financial services. The crypter is marketed on dark web forums, claiming to be 'the underground's most lethal crypter,' with tiered pricing from $450 to $2,000 per month. Proofpoint's research indicates that both production and testing samples of Cruciferra are actively being developed. The malware is delivered through methods like DLL side-loading, where a legitimate executable is paired with a malicious DLL. This DLL inspects the environment before dropping the payload, complicating detection efforts. The campaigns have been observed to have opportunistic targeting, with message volumes ranging from hundreds to thousands per campaign.
Key Points: • Cruciferra is a crypter service used by multiple cybercriminal groups since late 2025. • It employs advanced evasion techniques including process ghosting and kernel-driver abuse. • Proofpoint observed campaigns delivering various malware types, impacting sectors like financial services.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.