Cruciferra Crypter Utilizes Process Ghosting to Evade Detection in Cybersecurity Threats
A new crypter service known as Cruciferra is being used by various cyber-criminal groups to cloak malware, according to research by Proofpoint. First appearing on the Exploit forum in 2025, Cruciferra is now involved in numerous campaigns delivering malware such as AsyncRAT and Agent Tesla. The service employs techniques like process ghosting and kernel-driver abuse, alongside over 90 encryption routines, to evade detection. Cruciferra's method involves DLL side-loading, where a legitimate executable is paired with a malicious DLL to deliver the payload. The crypter also disables endpoint detection by unhooking monitoring systems and using vulnerable drivers to terminate security processes. This approach has been linked to campaigns targeting sectors like financial services, healthcare, and government, with a significant portion of attacks attributed to the Chinese-speaking group TA4922.