Cruciferra Crypter Service Utilized by Cyber-Criminals to Evade Detection in Malware Campaigns
A sophisticated crypter service known as Cruciferra is being used by various cyber-criminal groups to evade detection while delivering malicious payloads. According to a report by Infosecurity Magazine, Cruciferra employs advanced techniques such as process ghosting and kernel-driver abuse to cloak malware. First offered for sale in autumn 2025, the service supports numerous campaigns distributing malware like AsyncRAT, Agent Tesla, and Remcos. It offers tiered access ranging from $450 to $2,000 per month and is continuously developed with frequent updates. The service uses methods like DLL side-loading, where a legitimate executable is paired with a malicious DLL, and unhooks endpoint detection and response (EDR) monitoring before execution. It also disables kernel-level telemetry by exploiting vulnerable signed drivers. The payloads are unpacked using over 90 encryption routines, and a modified process ghosting technique is used for final execution. This technique includes kernel anti-peek measures to sa...