Cruciferra Crypter-as-a-Service Enables Stealthy Global Malware Campaigns
Cruciferra is a commercial crypter‑as‑a‑service that packages and obfuscates Windows malware, allowing it to evade antivirus and endpoint‑detection tools. The service, advertised since fall 2025 for $450‑$2,000 per month, uses techniques such as indirect system calls, API and Import Address Table unhooking, Bring‑Your‑Own‑Vulnerable‑Driver (BYOVD) attacks, privilege‑escalation, persistence via the Run key, and a customized form of Process Ghosting that leaves minimal forensic evidence.
Researchers at Proofpoint observed the tool delivering a wide range of payloads—including Agent Tesla, AsyncRAT, Remcos RAT, Snake Keylogger and XWorm—through DLL side‑loading and encrypted ZIP bundles. Campaigns have targeted sectors such as finance, healthcare, government and education, with tax‑themed phishing lures aimed at Indian taxpayers and a link to the China‑associated TA4922 cluster. Because each batch of samples uses a dynamically assembled encryption routine, static signatures are difficult to create, complicating detection and response efforts.
Entities: Agent Tesla · AsyncRAT · Cruciferra · Proofpoint · TA4922