Cruciferra is a Windows-focused crypter-as-a-service and malware-enablement platform marketed on cybercriminal forums since late 2025. It is used by multiple unrelated criminal groups to conceal, execute, and deploy commodity remote-access trojans and information stealers, including AsyncRAT, Agent Tesla, Remcos, XWorm, ValleyRAT, Snake Keylogger, Formbook, XLoader, and zgRAT. It has been observed in opportunistic campaigns affecting financial services, healthcare, government, education, manufacturing, hospitality, and travel organizations.
Cruciferra commonly executes through DLL side-loading, using a legitimate signed executable to load a malicious library. Its anti-analysis and defense-evasion features include decoy exports, environment checks, indirect system calls, API and Import Address Table unhooking, payload encryption with highly variable routines, and a customized Process Ghosting implementation designed to reduce on-disk artifacts and hinder EDR memory inspection. It can abuse vulnerable signed kernel drivers through bring-your-own-vulnerable-driver techniques to terminate antivirus and EDR processes. Available configurations also include UAC-bypass and persistence functionality.
Observed delivery chains have included phishing messages with government, tax, and hospitality-themed lures; archives and disk-image files containing executable-and-DLL pairs; and ClickFix activity on compromised websites that persuades victims to execute PowerShell commands. In 2026, Cruciferra was used alongside the ErrTraffic service in ClickFix campaigns targeting Windows users. That chain used DLL side-loading and process hollowing to deploy the Remus information stealer after disabling endpoint security controls. Multiple Cruciferra-enabled campaigns have been linked to the Chinese-speaking cybercrime cluster TA4922, which has reported overlap with Silver Fox.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
En août 2026 , l’équipe Threat Response Unit (TRU) d’eSentire publie une analyse technique détaillée de campagnes observées fin juillet 2026, combinant deux services Malware-as-a-Service (MaaS) : ErrTraffic et Cruciferra.
A visitor who follows the on-screen steps unknowingly runs a copied PowerShell command, opening the door to the Cruciferra loader and the Remus information stealer.
According to new research from Proofpoint published on July 20, the crypter, marketed as Cruciferra, was first offered for sale on the Exploit forum in autumn 2025 and now underpins dozens of campaigns delivering AsyncRAT, Agent Tesla, Remcos, XWorm, ValleyRAT and Snake Keylogger.
Proofpoint uncovered Cruciferra, a crypter-as-a-service that helps hackers evade antivirus and deliver malware in multiple campaigns.
26 distinct techniques documented for this family, organized by ATT&CK tactic.
Victims first land on a hacked WordPress site. An obfuscated ErrTraffic script sits inside the page.
Subsequent PowerShell stages use a legitimate Microsoft-signed program to side-load Cruciferra as mscoree.dll.
Attackers trick users into running PowerShell... The PowerShell command kicks off several stages.
API Hashing APIs needed for process enumeration and injection are resolved through a custom algorithm that hashes exports of kernel32.dll and ntdll.dll.
The lure copies a hidden PowerShell command to the clipboard. It then tells the user to open PowerShell and paste it. This social trick is called ClickFix.
The final payload is loaded into memory using a variant of Process Ghosting.
Then the loader uses process hollowing to inject the Remus information stealer into another signed binary, ServiceModelReg.exe.
This is a bring-your-own-vulnerable-driver technique, in which attackers use a real signed driver rather than an obviously malicious kernel component.
When the loader is configured with its privilege-bypass and security-killing options, it writes the driver to the Windows Temp directory, creates a service, and begins targeting defenses.
...then plants itself in the registry’s Run key under the unassuming name “putty” so it survives a reboot.
Cruciferra adds an extra layer of sophistication by patching ZwQueryVirtualMemory hooks and by attempting to tamper with the NtManageHotPatch routine to hide the deletion of the file and neutralize integrity checks.
The payload is a .NET 7.0 application compiled via NativeAOT, typically delivered through DLL side-loading.
...fake landing pages hosting ZIP files disguised as tax documents... One wave impersonated the US Social Security Administration...
The final payload is loaded into memory using a variant of Process Ghosting.
Then the loader uses process hollowing to inject the Remus information stealer into another signed binary, ServiceModelReg.exe.
Process Ghosting is when malware creates a temporary file, marks it for pending deletion via NtSetInformationFile... Once the file handle is closed, the operating system deletes the file from disk while the section persists in memory.
119 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A malware loader sold as a service that is delivered through ErrTraffic ClickFix lures. It uses DLL sideloading and process hollowing to deploy Remus, and can abuse the signed vulnerable DCRCVDrv.sys driver for kernel-level termination of 145 antivirus and EDR processes.
Loader MaaS sold on underground forums since November 2025. It uses DLL side-loading via a signed Microsoft binary, can perform process hollowing to inject payloads, and optionally abuses the vulnerable driver DCRCVDrv.sys for BYOVD-style AV/EDR termination.
A loader used in a MaaS campaign that is sideloaded via a legitimate Microsoft-signed binary, disables antivirus and EDR processes by abusing the vulnerable driver DCRCVDrv.sys from kernel mode, and uses process hollowing to inject a secondary payload.
A malware loader delivered via fake CAPTCHA/ClickFix lures that is side-loaded as mscoree.dll, uses process hollowing, and abuses a signed but vulnerable driver (DCRCVDrv.sys) to terminate antivirus and EDR processes before follow-on payloads execute.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.