This $2,000-a-Month Crypter Can Kill EDR and Make Malware Disappear From Disk

A criminal service called Cruciferra is giving malware operators a way to slip past Windows defenses.

Sold as a subscription crypter for as much as $2,000 a month, it wraps malicious programs so security tools struggle to inspect, block, and trace them.

The service has been active since fall 2025 and is advertised on underground forums.

Attackers have used email lures, fake tax portals, PDF links, ZIP archives, and virtual hard disk files to deliver it, putting financial, healthcare, government, travel, and hospitality organizations at risk.

Analysts at Proofpoint identified Cruciferra in dozens of campaigns. The tool has delivered remote-access trojans and information stealers, including AsyncRAT, XWorm, zgRAT, Agent Tesla, Formbook, Remcos, and XLoader.

A public advertisement and notice of Cruciferra (from exploit[.]in) (Source - Proofpoint)
A public advertisement and notice of Cruciferra (from exploit[.]in) (Source – Proofpoint)

Proofpoint said in a report shared with Cyber Security News (CSN) the immediate danger is not one payload, but the service behind it.

Buyers can conceal different malware families behind changing code, making signature-based detection less dependable and helping campaigns reach hundreds or thousands of targets.

This $2,000-a-Month Crypter Can Kill EDR

Cruciferra is written in Mono and runs through DLL side-loading. Victims receive an archive with an executable and DLL; when launched, Windows loads the malicious DLL and starts the crypter.

That pattern also appeared in an AsyncRAT DLL sideloading campaign, reinforcing why unexpected archives need careful scrutiny.

Before releasing its payload, Cruciferra checks whether it is running in a sandbox or analyst virtual machine.

Fake Income Tax Department portal used to host the ZIP file which initiates the Cruciferra infection chain (Source - Proofpoint)
Fake Income Tax Department portal used to host the ZIP file which initiates the Cruciferra infection chain (Source – Proofpoint)

It pads DLLs with harmless exported functions, hides console windows, and removes monitoring hooks from Windows functions commonly used by endpoint detection and response, or EDR, products.

Its most concerning option is a Bring Your Own Vulnerable Driver attack. Cruciferra can drop a signed vulnerable driver, then send low-level commands that terminate security processes.

The approach mirrors how trusted drivers can kill EDR, leaving an endpoint far less able to detect what follows.

The crypter also seeks administrator rights, changes registry settings to suppress Windows notifications, and creates persistence after reboot.

It relies on indirect system calls and Import Address Table repair to reduce visibility, reflecting the wider rise of recent EDR evasion framework abuse.

Malware That Vanishes

Cruciferra’s payload protection is designed for variation. Proofpoint found more than 90 encryption routines, many assembled from pieces of known algorithms rather than used unchanged.

Each build can look different to a scanner even when it performs the same job. The final execution step uses a customized form of Process Ghosting.

The malware writes a payload to a temporary file, marks it for deletion, maps it into memory, and allows Windows to remove the disk artifact.

Fraudulent SSA emails (Source - Proofpoint)
Fraudulent SSA emails (Source – Proofpoint)

It then redirects a suspended legitimate process to the payload and resumes it. The malicious program can keep running even though it was never available on disk in a normal scannable form.

Cruciferra further tries to disguise the deleted backing file when EDR checks memory and interferes with a Windows function that may validate loaded images.

In one campaign, tax-themed messages impersonated the Income Tax Department and led recipients to attacker-controlled ZIP downloads.

Other campaigns used U.S. Social Security Administration notices or guest complaint and bed-bug themes, with shortcut files launching PowerShell to begin the infection chain. It continues to monitor the service’s development and adoption.

Defenders should block vulnerable drivers, keep Windows and endpoint products updated, enable PowerShell logging, and carefully verify unexpected download requests, particularly those using urgent tax or complaint themes.

Indicators of compromise (IoCs):-

Type Indicator Description
URL hxxp://sahyteiows.gu.cc TA4922 Cruciferra AsyncRAT payload URL, first seen April 28, 2026
URL hxxp://yicoweytcbtw.gu.cc TA4922 Cruciferra AsyncRAT payload URL, first seen April 28, 2026
URL hxxp://nciyeyrawoe.gu.cc TA4922 Cruciferra AsyncRAT payload URL, first seen April 28, 2026
URL hxxp://lasiduutfe.gu.cc TA4922 Cruciferra AsyncRAT payload URL, first seen April 28, 2026
SHA-256 3c181f642e24c28602a87be7f195e2f3d1ffa30b37e20f5121d99f88b22ab80e Tax-Number52563.zip, TA4922 Cruciferra AsyncRAT
URL hxxp://xkcifgieusr.gu.cc TA4922 Cruciferra AsyncRAT payload URL, first seen May 4, 2026
URL hxxp://viuyeyrwqs.gu.cc TA4922 Cruciferra AsyncRAT payload URL, first seen May 4, 2026
URL hxxp://pmcjsuyraw.gu.cc TA4922 Cruciferra AsyncRAT payload URL, first seen May 4, 2026
URL hxxp://laiwutrencr.gu.cc TA4922 Cruciferra AsyncRAT payload URL, first seen May 4, 2026
URL hxxp://maisytawe.gu.cc TA4922 Cruciferra AsyncRAT payload URL, first seen May 4, 2026
URL hxxp://kawosyetw.gu.cc TA4922 Cruciferra AsyncRAT payload URL, first seen May 4, 2026
URL hxxp://nviuawusye.gu.cc TA4922 Cruciferra AsyncRAT payload URL, first seen May 4, 2026
URL hxxp://faeytrdeaw.gu.cc TA4922 Cruciferra AsyncRAT payload URL, first seen May 4, 2026
URL hxxp://figyuyrqwr.gu.cc TA4922 Cruciferra AsyncRAT payload URL, first seen May 4, 2026
URL hxxp://hfyuayustrv.gu.cc TA4922 Cruciferra AsyncRAT payload URL, first seen May 4, 2026
URL hxxp://jsiruytrawey.gu.cc TA4922 Cruciferra AsyncRAT payload URL, first seen May 4, 2026
URL hxxp://kawuuterta.gu.cc TA4922 Cruciferra AsyncRAT payload URL, first seen May 4, 2026
URL hxxp://nvsieyrrawe.gu.cc TA4922 Cruciferra AsyncRAT payload URL, first seen May 4, 2026
SHA-256 66dbe675480dc229e5b3ab8ad74207f73486e64e57805074f784bb2e01bcb865 Tax-Number809863.zip, TA4922 Cruciferra AsyncRAT
URL hxxp://fuaytrwese.love TA4922 Cruciferra AsyncRAT payload URL, first seen May 28, 2026
URL hxxp://qeuasytua.love TA4922 Cruciferra AsyncRAT payload URL, first seen May 28, 2026
URL hxxp://svuatwea.love TA4922 Cruciferra AsyncRAT payload URL, first seen May 28, 2026
URL hxxp://vusuydryt.love TA4922 Cruciferra AsyncRAT payload URL, first seen May 28, 2026
URL hxxp://xnbscuya.love TA4922 Cruciferra AsyncRAT payload URL, first seen May 28, 2026
URL hxxp://ncduuyese.live TA4922 Cruciferra AsyncRAT payload URL, first seen May 28, 2026
URL hxxp://soakwusya.love TA4922 Cruciferra AsyncRAT payload URL, first seen May 28, 2026
URL hxxp://syfiaydytea.live TA4922 Cruciferra AsyncRAT payload URL, first seen May 28, 2026
SHA-256 a6fb779be35592fb0ff624a8f8e12ab3cafe7bcfc312cd98263814db7fb01e02 Tax-Number119863.zip, TA4922 Cruciferra AsyncRAT
SHA-256 59ad96dd3b4d5f10a5c53bbd465446e52dc7701a4ac633632f762bf1336d3347 Tax-Number101863.zip, TA4922 Cruciferra AsyncRAT
URL hxxp://jaiydteds.love TA4922 Cruciferra AsyncRAT payload URL, first seen June 1, 2026
URL hxxp://mksfuuerwo.live TA4922 Cruciferra AsyncRAT payload URL, first seen June 1, 2026
URL hxxp://fiusyevr.live TA4922 Cruciferra AsyncRAT payload URL, first seen June 1, 2026
URL hxxp://lisiutegrm.live TA4922 Cruciferra AsyncRAT payload URL, first seen June 1, 2026
URL hxxp://paiwudyea.love TA4922 Cruciferra AsyncRAT payload URL, first seen June 1, 2026
URL hxxp://xuastyrdqk.love TA4922 Cruciferra AsyncRAT payload URL, first seen June 1, 2026
URL hxxp://sfvxcuvuyte.live TA4922 Cruciferra AsyncRAT payload URL, first seen June 1, 2026
URL hxxp://skdsuyrse.live TA4922 Cruciferra AsyncRAT payload URL, first seen June 1, 2026
URL hxxp://shsauyeet.live TA4922 Cruciferra AsyncRAT payload URL, first seen June 1, 2026
SHA-256 6dbd6f9f2fa636c16ac4fa81418b68a604424861b9650dd9c4f2b0ba6f67d6ac Tax-Number33863.zip, TA4922 Cruciferra AsyncRAT
URL hxxp://almacensantangel.com/wp-includes/assets/YourSSADocuments0000000676152051872026Document0000000676152.rar Cruciferra XWorm payload URL
Domain gatuso.duckdns.org XWorm command-and-control server
SHA-256 3f31aee0948d16f8d64bf6bec69a4331099993e502b11bfc56b2c0112024489d photo295825092412.zip, Cruciferra zgRAT payload
URL hxxp://digital-magicians.com/photo295825092412.zip?rea623202 Cruciferra zgRAT payload URL
Domain 0zbqnac1t4dv2t2wuodv1m.com zgRAT command-and-control server
IP address and port 89.34.90.99:56001 zgRAT command-and-control server
Driver and SHA-256 Core64.sys / 17aae57cf6255c7eb169bf62ea67376d9708976eb7831f8cdd0ea38bdcb37dc4 Vulnerable helper driver used for BYOVD evasion
Driver and SHA-256 GoFlyDrv.sys / 2fdfdd13a0c548bb68c9d5aa8599a9265d4659da3e237fe7a42ac6ac06b9a06a Vulnerable helper driver used for BYOVD evasion
Driver and SHA-256 HwOs2Ec.sys / c4e93449453cf67c5d5605bb8f425207a738a242fdb432d720acc32faa74926c Vulnerable helper driver used for BYOVD evasion
Driver and SHA-256 LnvMSRIO.sys / c5b1e9aafc8f2b4ab05effc00fd43f3114b9ef1d592a086c952793ac4e299809 Vulnerable helper driver used for BYOVD evasion
Driver and SHA-256 MemoryInformer.sys / 7887e919555fb5948c217556ba149392a72982b1bc427d3db779db9dcbf09ee8 Vulnerable helper driver used for BYOVD evasion
Driver and SHA-256 NTIOLibX64.sys / 09bedbf7a41e0f8dabe4f41d331db58373ce15b2e9204540873a1884f38bdde1 Vulnerable helper driver used for BYOVD evasion
Driver and SHA-256 ProcessMonitorDriver.sys / 5b4f59236a9b950bcd5191b35d19125f60cfb9e1a1e1aa2e4f914b6745dde9df Vulnerable helper driver used for BYOVD evasion
Driver and SHA-256 selfprot.sys / c46e907886e2158cbc453e767183aecf07887b5ac8848f19684451883d69f5f0 Vulnerable helper driver used for BYOVD evasion

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

! ALERT: 20+ government sites delivered malware to businesses and citizens. See full attack research to check your own exposure

The post This $2,000-a-Month Crypter Can Kill EDR and Make Malware Disappear From Disk appeared first on Cyber Security News.