Cruciferra is the seller and namesake of a malware-as-a-service operation active since at least November 2025. Its offerings include the PUROSANGUE loader package and the COCONUT package. PUROSANGUE has been used in Windows-focused ClickFix intrusion chains delivered through compromised websites, where victims are socially engineered into executing PowerShell commands. The loader employs DLL side-loading and process hollowing to deploy information stealers including Remus and Rapuncel. It supports UAC-bypass attempts, service-based persistence, and security-tool impairment. Cruciferra packages have incorporated bring-your-own-vulnerable-driver techniques to terminate antivirus and endpoint-detection processes from kernel mode, including processes protected from ordinary user-mode termination. Rapuncel-enabled deployments have stolen browser credentials, cryptocurrency-wallet data, messaging and gaming-session data, Windows Credential Manager contents, selected documents, screenshots, and host information, and exfiltrated collected data in compressed archives. Cruciferra is marketed on underground forums on a subscription basis, indicating a financially motivated malware-as-a-service business model. The identities of operators conducting campaigns using Cruciferra products are not established.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
13 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A malware-as-a-service seller whose Cruciferra loader is delivered through ClickFix campaigns and deploys the Remus information stealer. Its PUROSANGUE package includes an EDR-killing capability using a signed vulnerable driver.
Operator/vendor associated with the Cruciferra MaaS loader used in campaigns for DLL side-loading, process hollowing, Remus stealer delivery, and optional BYOVD-based AV/EDR termination.
A crypter-service operation whose PUROSANGUE package is assessed as the likely source or close lineage of the malicious side-loaded loader. The package is associated with DLL side-loading, payload storage in the .reloc section using a custom Base16 alphabet, UAC bypass, persistence, BYOVD-style endpoint-defense tampering, process hollowing, and targeting of 145 AV/EDR processes.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.