This $2,000-a-Month Crypter Can Kill EDR and Make Malware Disappear From Disk
A criminal service called Cruciferra is giving malware operators a way to slip past Windows defenses. Sold as a subscription crypter for as much as $2,000 a month, it wraps malicious programs so secur

A criminal service called Cruciferra is giving malware operators a way to slip past Windows defenses. Sold as a subscription crypter for as much as $2,000 a month, it wraps malicious programs so security tools struggle to inspect, block, and trace them. The service has been active since fall 2025 and is advertised on underground […] The post This $2,000-a-Month Crypter Can Kill EDR and Make Malware Disappear From Disk appeared first on Cyber Security News.
A criminal service called Cruciferra is giving malware operators a way to slip past Windows defenses. Sold as a subscription crypter for as much as $2,000 a month, it wraps malicious programs so security tools struggle to inspect, block, and trace them. The service has been active since fall 2025 and is advertised on underground forums. Attackers have used email lures, fake tax portals, PDF links, ZIP archives, and virtual hard disk files to deliver it, putting financial, healthcare, government, travel, and hospitality organizations at risk. Analysts at Proofpoint identified Cruciferra in dozens of campaigns. The tool has delivered remote-access trojans and information stealers, including AsyncRAT, XWorm, zgRAT, Agent Tesla, Formbook, Remcos, and XLoader. A public advertisement and notice of Cruciferra (from exploit[.]in) (Source – Proofpoint) Proofpoint said in a report shared with Cyber Security News (CSN) the immediate danger is not one payload, but the service behind it. Buyers can conceal different malware families behind changing code, making signature-based detection less dependable and helping campaigns reach hundreds or thousands of targets. This $2,000-a-Month Crypter Can Kill EDR Cruciferra is written in Mono and runs through DLL side-loading. Victims receive an archive with an executable and DLL; when launched, Windows loads the malicious DLL and starts the crypter. That pattern also appeared in an AsyncRAT DLL sideloading campaign, reinforcing why unexpected archives need careful scrutiny. Before releasing its payload, Cruciferra checks whether it is running in a sandbox or analyst virtual machine. Fake Income Tax Department portal used to host the ZIP file which initiates the Cruciferra infection chain (Source – Proofpoint) It pads DLLs with harmless exported functions, hides console windows, and removes monitoring hooks from Windows functions commonly used by endpoint detection and response, or EDR, products. Its most concerning option is a Bring Your Own Vulnerable Driver attack. Cruciferra can drop a signed vulnerable driver, then send low-level commands that terminate security processes. The approach mirrors how trusted drivers can kill EDR, leaving an endpoint far less able to detect what follows. The crypter also seeks administrator rights, changes registry settings to suppress Windows notifications, and creates persistence after reboot. It relies on indirect system calls and Import Address Table repair to reduce visibility, reflecting the wider rise of recent EDR evasion framework abuse. Malware That Vanishes Cruciferra’s payload protection is designed for variation. Proofpoint found more than 90 encryption routines, many assembled from pieces of known algorithms rather than used unchanged. Each build can look different to a scanner even when it performs the same job. The final execution step uses a customized form of Process Ghosting. The malware writes a payload to a temporary file, marks it for deletion, maps it into memory, and allows Windows to remove the disk artifact. Fraudulent SSA emails (Source – Proofpoint) It then redirects a suspended legitimate process to the payload and resumes it. The malicious program can keep running even though it was never available on disk in a normal scannable form. Cruciferra further tries to disguise the deleted backing file when EDR checks memory and interferes with a Windows function that may validate loaded images. In one campaign, tax-themed messages impersonated the Income Tax Department and led recipients to attacker-controlled ZIP downloads. Other campaigns used U.S. Social Security Administration notices or guest complaint and bed-bug themes, with shortcut files launching PowerShell to begin the infection chain. It continues to monitor the service’s development and adoption. Defenders should block vulnerable drivers, keep Windows and endpoint products updated, enable PowerShell logging, and carefully verify unexpected download requests, particularly those using urgent tax or complaint themes. Indicators of compromise (IoCs):- TypeIndicatorDescriptionURLhxxp://sahyteiows.gu.ccTA4922 Cruciferra AsyncRAT payload URL, first seen April 28, 2026URLhxxp://yicoweytcbtw.gu.ccTA4922 Cruciferra AsyncRAT payload URL, first seen April 28, 2026URLhxxp://nciyeyrawoe.gu.ccTA4922 Cruciferra AsyncRAT payload URL, first seen April 28, 2026URLhxxp://lasiduutfe.gu.ccTA4922 Cruciferra AsyncRAT payload URL, first seen April 28, 2026SHA-2563c181f642e24c28602a87be7f195e2f3d1ffa30b37e20f5121d99f88b22ab80eTax-Number52563.zip, TA4922 Cruciferra AsyncRATURLhxxp://xkcifgieusr.gu.ccTA4922 Cruciferra AsyncRAT payload URL, first seen May 4, 2026URLhxxp://viuyeyrwqs.gu.ccTA4922 Cruciferra AsyncRAT payload URL, first seen May 4, 2026URLhxxp://pmcjsuyraw.gu.ccTA4922 Cruciferra AsyncRAT payload URL, first seen May 4, 2026URLhxxp://laiwutrencr.gu.ccTA4922 Cruciferra AsyncRAT payload URL, first seen May 4, 2026URLhxxp://maisytawe.gu.ccTA4922 Cruciferra AsyncRAT payload URL, first seen May 4, 2026URLhxxp://kawosyetw.gu.ccTA4922 Cruciferra AsyncRAT payload URL, first seen May 4, 2026URLhxxp://nviuawusye.gu.ccTA4922 Cruciferra AsyncRAT payload URL, first seen May 4, 2026URLhxxp://faeytrdeaw.gu.ccTA4922 Cruciferra AsyncRAT payload URL, first seen May 4, 2026URLhxxp://figyuyrqwr.gu.ccTA4922 Cruciferra AsyncRAT payload URL, first seen May 4, 2026URLhxxp://hfyuayustrv.gu.ccTA4922 Cruciferra AsyncRAT payload URL, first seen May 4, 2026URLhxxp://jsiruytrawey.gu.ccTA4922 Cruciferra AsyncRAT payload URL, first seen May 4, 2026URLhxxp://kawuuterta.gu.ccTA4922 Cruciferra AsyncRAT payload URL, first seen May 4, 2026URLhxxp://nvsieyrrawe.gu.ccTA4922 Cruciferra AsyncRAT payload URL, first seen May 4, 2026SHA-25666dbe675480dc229e5b3ab8ad74207f73486e64e57805074f784bb2e01bcb865Tax-Number809863.zip, TA4922 Cruciferra AsyncRATURLhxxp://fuaytrwese.loveTA4922 Cruciferra AsyncRAT payload URL, first seen May 28, 2026URLhxxp://qeuasytua.loveTA4922 Cruciferra AsyncRAT payload URL, first seen May 28, 2026URLhxxp://svuatwea.loveTA4922 Cruciferra AsyncRAT payload URL, first seen May 28, 2026URLhxxp://vusuydryt.loveTA4922 Cruciferra AsyncRAT payload URL, first seen May 28, 2026URLhxxp://xnbscuya.loveTA4922 Cruciferra AsyncRAT payload URL, first seen May 28, 2026URLhxxp://ncduuyese.liveTA4922 Cruciferra AsyncRAT payload URL, first seen May 28, 2026URLhxxp://soakwusya.loveTA4922 Cruciferra AsyncRAT payload URL, first seen May 28, 2026URLhxxp://syfiaydytea.liveTA4922 Cruciferra AsyncRAT payload URL, first seen May 28, 2026SHA-256a6fb779be35592fb0ff624a8f8e12ab3cafe7bcfc312cd98263814db7fb01e02Tax-Number119863.zip, TA4922 Cruciferra AsyncRATSHA-25659ad96dd3b4d5f10a5c53bbd465446e52dc7701a4ac633632f762bf1336d3347Tax-Number101863.zip, TA4922 Cruciferra AsyncRATURLhxxp://jaiydteds.loveTA4922 Cruciferra AsyncRAT payload URL, first seen June 1, 2026URLhxxp://mksfuuerwo.liveTA4922 Cruciferra AsyncRAT payload URL, first seen June 1, 2026URLhxxp://fiusyevr.liveTA4922 Cruciferra AsyncRAT payload URL, first seen June 1, 2026URLhxxp://lisiutegrm.liveTA4922 Cruciferra AsyncRAT payload URL, first seen June 1, 2026URLhxxp://paiwudyea.loveTA4922 Cruciferra AsyncRAT payload URL, first seen June 1, 2026URLhxxp://xuastyrdqk.loveTA4922 Cruciferra AsyncRAT payload URL, first seen June 1, 2026URLhxxp://sfvxcuvuyte.liveTA4922 Cruciferra AsyncRAT payload URL, first seen June 1, 2026URLhxxp://skdsuyrse.liveTA4922 Cruciferra AsyncRAT payload URL, first seen June 1, 2026URLhxxp://shsauyeet.liveTA4922 Cruciferra AsyncRAT payload URL, first seen June 1, 2026SHA-2566dbd6f9f2fa636c16ac4fa81418b68a604424861b9650dd9c4f2b0ba6f67d6acTax-Number33863.zip, TA4922 Cruciferra AsyncRATURLhxxp://almacensantangel.com/wp-includes/assets/YourSSADocuments0000000676152051872026Document0000000676152.rarCruciferra XWorm payload URLDomaingatuso.duckdns.orgXWorm command-and-control serverSHA-2563f31aee0948d16f8d64bf6bec69a4331099993e502b11bfc56b2c0112024489dphoto295825092412.zip, Cruciferra zgRAT payloadURLhxxp://digital-magicians.com/photo295825092412.zip?rea623202Cruciferra zgRAT payload URLDomain0zbqnac1t4dv2t2wuodv1m.comzgRAT command-and-control serverIP address and port89.34.90.99:56001zgRAT command-and-control serverDriver and SHA-256Core64.sys / 17aae57cf6255c7eb169bf62ea67376d9708976eb7831f8cdd0ea38bdcb37dc4Vulnerable helper driver used for BYOVD evasionDriver and SHA-256GoFlyDrv.sys / 2fdfdd13a0c548bb68c9d5aa8599a9265d4659da3e237fe7a42ac6ac06b9a06aVulnerable helper driver used for BYOVD evasionDriver and SHA-256HwOs2Ec.sys / c4e93449453cf67c5d5605bb8f425207a738a242fdb432d720acc32faa74926cVulnerable helper driver used for BYOVD evasionDriver and SHA-256LnvMSRIO.sys / c5b1e9aafc8f2b4ab05effc00fd43f3114b9ef1d592a086c952793ac4e299809Vulnerable helper driver used for BYOVD evasionDriver and SHA-256MemoryInformer.sys / 7887e919555fb5948c217556ba149392a72982b1bc427d3db779db9dcbf09ee8Vulnerable helper driver used for BYOVD evasionDriver and SHA-256NTIOLibX64.sys / 09bedbf7a41e0f8dabe4f41d331db58373ce15b2e9204540873a1884f38bdde1Vulnerable helper driver used for BYOVD evasionDriver and SHA-256ProcessMonitorDriver.sys / 5b4f59236a9b950bcd5191b35d19125f60cfb9e1a1e1aa2e4f914b6745dde9dfVulnerable helper driver used for BYOVD evasionDriver and SHA-256selfprot.sys / c46e907886e2158cbc453e767183aecf07887b5ac8848f19684451883d69f5f0Vulnerable helper driver used for BYOVD evasion Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM. ! ALERT: 20+ government sites delivered malware to businesses and citizens. See full attack research to check your own exposure The post This $2,000-a-Month Crypter Can Kill EDR and Make Malware Disappear From Disk appeared first on Cyber Security News.
Join the Discussion
Comments coming soon. Follow us on social media for real-time discussions.


