Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
eSentire describes a Cruciferra package called PUROSANGUE that produces a NativeAOT side-loaded DLL with EDR/AV killing, COM Elevation Moniker UAC bypass, process hollowing into ServiceModelReg.exe, and 145 default AV/EDR process targets.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
eSentire describes a Cruciferra package called PUROSANGUE that produces... process hollowing into ServiceModelReg.exe.
Alinubx.sys is a renamed, identity-swapped version of CcProtect.sys... a driver already listed on LOLDrivers with public proof-of-concept killer code.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Cruciferra crypter package likely used to produce the malicious DLL loaded by the fake installer; it has been associated with side-loaded DLL payloads containing code to disable endpoint detection and antivirus products.
Crypter used to build the loader delivering Rapuncel in this campaign.
A Cruciferra crypter package or closely related derivative assessed as the source lineage for the malicious vsdbg.dll NativeAOT side-loaded loader. Its described functions include EDR/AV process killing, UAC bypass, persistence, DLL side-loading, and process hollowing.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.