By Interestana AI Editorial — AI-drafted, human-overseen. How we report
Cruciferra Crypter Evades Detection With BYOVD and Ghosting

The sophisticated crypter service known as Cruciferra is being employed by China-linked cybercrime groups to evade detection when delivering malware, according to new analysis by Proofpoint. This crypter has been observed in use by multiple, distinct cybercriminal threat clusters, indicating its broad utility in distributing a variety of remote access trojans (RATs) and other malicious payloads. The threat actors leveraging Cruciferra have recently targeted Indian taxpayers, tax professionals, and corporate finance teams using phishing lures related to income tax.
Cruciferra's effectiveness stems from its advanced evasion techniques, notably the use of Bring Your Own Vulnerable Driver (BYOVD) and process ghosting. BYOVD involves exploiting legitimate, but vulnerable, drivers already present on a victim's system to gain elevated privileges and execute malicious code. This method circumvents many security measures that focus on detecting the introduction of new, unsigned drivers. Process ghosting is another technique that makes it difficult for security software to monitor and analyze running processes. It involves creating a process in a suspended state, modifying its memory, and then resuming it, effectively hiding its initial creation and execution from standard process enumeration tools.
Proofpoint's analysis highlights that Cruciferra is not tied to a single threat actor but is instead a service utilized by various unrelated cybercriminal operations. This suggests a commercial or shared infrastructure model for the crypter, making it accessible to a wider range of malicious actors. The observed phishing campaigns, which utilize income tax-related themes, are designed to trick recipients into opening malicious attachments or clicking on malicious links, thereby initiating the malware infection chain. The sophistication of Cruciferra indicates a significant investment in evasion capabilities by the threat actors, posing a persistent challenge to cybersecurity defenses.
The implications of Cruciferra's deployment are far-reaching, as it enables threat actors to more effectively deliver a diverse range of malware, including RATs that can provide attackers with extensive control over compromised systems. This control can be used for data theft, espionage, further network infiltration, or deploying ransomware. The targeting of financial professionals and taxpayers in India suggests a focus on financial gain or disruption within specific economic sectors. The continuous evolution of such crypters underscores the ongoing arms race between cybercriminals and security researchers, necessitating constant updates to detection and prevention strategies.
Original source — read the full reporting at the publisher:
Read on The Hacker NewsGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.