Cruciferra is a Windows-focused crypter-as-a-service and malware loader sold on cybercriminal forums since late 2025. It is used by multiple unrelated cybercriminal clusters to obfuscate, execute, and deliver commodity remote-access trojans and information stealers, including AsyncRAT, Agent Tesla, Remcos, XWorm, ValleyRAT, Snake Keylogger, and zgRAT. Observed execution commonly relies on DLL sideloading with a legitimate executable and malicious DLL pair.
Cruciferra incorporates extensive defense-evasion functionality, including anti-analysis decoy exports, indirect system calls, API and Import Address Table unhooking, polymorphic payload encryption, and a modified Process Ghosting implementation intended to limit on-disk and memory-inspection visibility. It can use bring-your-own-vulnerable-driver techniques to terminate antivirus and EDR processes from kernel mode, and observed variants support privilege escalation, persistence, and process hollowing to execute follow-on payloads. Some campaigns used Cruciferra to inject the Remus information stealer into a signed Windows process.
Cruciferra-enabled operations have used phishing, deceptive landing pages, ZIP-based lures, and ClickFix social engineering delivered through compromised websites. One observed set of campaigns used compromised WordPress sites and fake verification prompts to induce victims to execute PowerShell commands. TA4922, a Chinese-speaking cybercrime group with reported overlap with Silver Fox, has been linked to some tax-themed Cruciferra campaigns targeting Indian taxpayers, tax professionals, and corporate finance personnel. Targeting across the broader Cruciferra ecosystem has been opportunistic, with financial services, healthcare, government, education, manufacturing, hospitality, and travel organizations affected.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
En août 2026 , l’équipe Threat Response Unit (TRU) d’eSentire publie une analyse technique détaillée de campagnes observées fin juillet 2026, combinant deux services Malware-as-a-Service (MaaS) : ErrTraffic et Cruciferra.
A visitor who follows the on-screen steps unknowingly runs a copied PowerShell command, opening the door to the Cruciferra loader and the Remus information stealer.
According to new research from Proofpoint published on July 20, the crypter, marketed as Cruciferra, was first offered for sale on the Exploit forum in autumn 2025 and now underpins dozens of campaigns delivering AsyncRAT, Agent Tesla, Remcos, XWorm, ValleyRAT and Snake Keylogger.
Proofpoint uncovered Cruciferra, a crypter-as-a-service that helps hackers evade antivirus and deliver malware in multiple campaigns.
25 distinct techniques documented for this family, organized by ATT&CK tactic.
Victims first land on a hacked WordPress site. An obfuscated ErrTraffic script sits inside the page.
Subsequent PowerShell stages use a legitimate Microsoft-signed program to side-load Cruciferra as mscoree.dll.
Attackers trick users into running PowerShell... The PowerShell command kicks off several stages.
API Hashing APIs needed for process enumeration and injection are resolved through a custom algorithm that hashes exports of kernel32.dll and ntdll.dll.
The lure copies a hidden PowerShell command to the clipboard. It then tells the user to open PowerShell and paste it. This social trick is called ClickFix.
The final payload is loaded into memory using a variant of Process Ghosting.
Then the loader uses process hollowing to inject the Remus information stealer into another signed binary, ServiceModelReg.exe.
This is a bring-your-own-vulnerable-driver technique, in which attackers use a real signed driver rather than an obviously malicious kernel component.
The loader then tries three ways to gain administrator rights, reaches SYSTEM, the highest level on a Windows machine, and installs the kernel driver as a service.
...then plants itself in the registry’s Run key under the unassuming name “putty” so it survives a reboot.
Cruciferra adds an extra layer of sophistication by patching ZwQueryVirtualMemory hooks and by attempting to tamper with the NtManageHotPatch routine to hide the deletion of the file and neutralize integrity checks.
The payload is a .NET 7.0 application compiled via NativeAOT, typically delivered through DLL side-loading.
...fake landing pages hosting ZIP files disguised as tax documents... One wave impersonated the US Social Security Administration...
The final payload is loaded into memory using a variant of Process Ghosting.
Then the loader uses process hollowing to inject the Remus information stealer into another signed binary, ServiceModelReg.exe.
Process Ghosting is when malware creates a temporary file, marks it for pending deletion via NtSetInformationFile... Once the file handle is closed, the operating system deletes the file from disk while the section persists in memory.
119 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
18 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A paid crypter/loader assessed with high confidence to have been used to build the campaign loader. Its default security-process kill list contains 145 entries, and it supports interchangeable kernel drivers.
A crypter service linked to the Rapuncel infection chain through the malicious side-loaded DLL. Its PUROSANGUE package was likely used to create the DLL and had previously produced DLLs containing EDR/antivirus-killing code.
A malware loader sold as a service that is delivered through ErrTraffic ClickFix lures. It uses DLL sideloading and process hollowing to deploy Remus, and can abuse the signed vulnerable DCRCVDrv.sys driver for kernel-level termination of 145 antivirus and EDR processes.
Loader MaaS sold on underground forums since November 2025. It uses DLL side-loading via a signed Microsoft binary, can perform process hollowing to inject payloads, and optionally abuses the vulnerable driver DCRCVDrv.sys for BYOVD-style AV/EDR termination.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.