Cruciferra is a subscription-based crypter-as-a-service used by multiple unrelated cybercriminal actors to conceal and deliver commodity malware on Windows systems. Active since at least late 2025, it has been used to wrap and deploy a range of payloads including remote access trojans, infostealers, and keyloggers such as AsyncRAT, Agent Tesla, Remcos, XWorm, zgRAT, Formbook, XLoader, Phantom Stealer, and related families. It functions as a malware-enablement service rather than a single payload family, improving delivery success by heavily obfuscating embedded or downloaded malware and reducing the effectiveness of static analysis, signature-based detection, and endpoint monitoring.
Cruciferra is built on Mono and is consistently executed through DLL side-loading, typically pairing a legitimate executable with a malicious DLL. Its evasion stack is unusually extensive for a commercial crypter service and includes API and Import Address Table unhooking, indirect system calls, sandbox and virtual-machine checks, decoy exports, suppression of visible console artifacts, and highly variable payload protection using dozens of custom or hybrid encryption routines. It also incorporates Bring Your Own Vulnerable Driver techniques to tamper with or terminate security tooling, seeks elevated privileges, modifies system settings to reduce user-facing notifications, and can establish persistence across reboots.
A notable feature of Cruciferra is its customized implementation of Process Ghosting for final payload execution. This allows payloads to be mapped and launched with minimal disk artifacts while reducing defender visibility into the backing image. Additional anti-analysis measures have included interference with memory inspection and image-validation-related telemetry, further complicating forensic inspection and endpoint detection.
Cruciferra has appeared in dozens of campaigns conducted by different threat actors, including activity attributed in some cases to TA4922. Observed delivery chains have included email-borne lures, archive-based attachments, virtual hard disk files, shortcut-based execution chains, and themed social-engineering content such as tax, government-notice, and hospitality complaints. Targeting has been largely opportunistic, but financial services, healthcare, government, travel, and hospitality organizations have featured prominently among observed victims.
Cruciferra is best understood as an actively maintained crypter platform within the cybercrime ecosystem that enables downstream malware operators to improve stealth, bypass Windows defenses, and operationalize commodity malware at scale.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
A criminal service called Cruciferra is giving malware operators a way to slip past Windows defenses. Sold as a subscription crypter for as much as $2,000 a month, it wraps malicious programs so security tools struggle to inspect, block, and trace them.
18 distinct techniques documented for this family, organized by ATT&CK tactic.
Attackers have used email lures, fake tax portals, PDF links, ZIP archives, and virtual hard disk files to deliver it... In one campaign, tax-themed messages impersonated the Income Tax Department... Other campaigns used U.S. Social Security Administration notices or guest complaint and bed-bug themes.
The crypter also seeks administrator rights, changes registry settings to suppress Windows notifications, and creates persistence after reboot.
The final execution step uses a customized form of Process Ghosting. The malware writes a payload to a temporary file, marks it for deletion, maps it into memory, and allows Windows to remove the disk artifact. It then redirects a suspended legitimate process to the payload and resumes it.
Its most concerning option is a Bring Your Own Vulnerable Driver attack. Cruciferra can drop a signed vulnerable driver, then send low-level commands that terminate security processes.
The crypter also seeks administrator rights, changes registry settings to suppress Windows notifications, and creates persistence after reboot.
The crypter also focuses heavily on payload protection through numerous custom encryption methods that vary across samples. This constant variation makes static analysis and signature-based detection much more difficult for defenders.
The final execution step uses a customized form of Process Ghosting. The malware writes a payload to a temporary file, marks it for deletion, maps it into memory, and allows Windows to remove the disk artifact. It then redirects a suspended legitimate process to the payload and resumes it.
Payloads are encoded in the binary using Base16 encoding with a custom character set... After the decoding stage, the payloads... are stored in a simple file structure.
It relies on indirect system calls and Import Address Table repair to reduce visibility...
This script first fingerprinted the user's system and reported the collected information to an actor-controlled server.
108 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A malware crypter service used to wrap and obfuscate payloads so they evade Windows security controls and EDR. The content says it uses DLL side-loading, sandbox/VM checks, BYOVD to terminate security processes, indirect syscalls, IAT repair, persistence mechanisms, and a customized Process Ghosting technique to execute payloads while minimizing disk artifacts and detection.
A crypter service used by multiple unrelated cybercriminal groups to conceal and deliver commodity malware. It uses DLL side-loading, EDR unhooking, Import Address Table patching, vulnerable signed drivers to disable kernel telemetry, numerous encryption routines, and a modified process ghosting technique with kernel anti-peek measures.
Cruciferra is a Mono-built crypter service designed to hide malware payloads and improve delivery success. The content says it uses indirect system calls, API/IAT unhooking, BYOVD-based EDR tampering, privilege escalation, persistence, Process Ghosting, and varied custom encryption methods to evade analysis and detection.
A malware-as-a-service crypter used to conceal, protect, and deliver other malware payloads. It uses extensive anti-analysis and defense-evasion techniques including DLL side-loading, indirect syscalls, API/IAT unhooking, BYOVD-based EDR tampering, UAC bypass, persistence, custom payload encryption, and a tweaked Process Ghosting implementation to execute payloads while minimizing forensic artifacts.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.