A criminal service called Cruciferra is giving malware operators a way to slip past Windows defenses.
Sold as a subscription crypter for as much as $2,000 a month, it wraps malicious programs so security tools struggle to inspect, block, and trace them.
The service has been active since fall 2025 and is advertised on underground forums.
Attackers have used email lures, fake tax portals, PDF links, ZIP archives, and virtual hard disk files to deliver it, putting financial, healthcare, government, travel, and hospitality organizations at risk.
Analysts at Proofpoint identified Cruciferra in dozens of campaigns. The tool has delivered remote-access trojans and information stealers, including AsyncRAT, XWorm, zgRAT, Agent Tesla, Formbook, Remcos, and XLoader.
![A public advertisement and notice of Cruciferra (from exploit[.]in) (Source - Proofpoint)](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh9TTkWtOke_7sTD4I-uJma87D7P9neGi5pTFAiCV0svlUQhPOkkPt3sxcfFOsikVUot_zfURLw77ii-ONccSE6x1oxF0Xo94kQrlkZlUmTg7sKQRhy84Ib3hbjTmq9NdApj9Bh0W583g7lgKdOiq9n4bDmY-UbkU3crymEwQJpHQvmiPkYz3FOiXLqBbc/s1600/A%20public%20advertisement%20and%20notice%20of%20Cruciferra%20(from%20exploit%5B.%5Din)%20(Source%20-%20Proofpoint).webp)
Proofpoint said in a report shared with Cyber Security News (CSN) the immediate danger is not one payload, but the service behind it.
Buyers can conceal different malware families behind changing code, making signature-based detection less dependable and helping campaigns reach hundreds or thousands of targets.
This $2,000-a-Month Crypter Can Kill EDR
Cruciferra is written in Mono and runs through DLL side-loading. Victims receive an archive with an executable and DLL; when launched, Windows loads the malicious DLL and starts the crypter.
That pattern also appeared in an AsyncRAT DLL sideloading campaign, reinforcing why unexpected archives need careful scrutiny.
Before releasing its payload, Cruciferra checks whether it is running in a sandbox or analyst virtual machine.
.webp)
It pads DLLs with harmless exported functions, hides console windows, and removes monitoring hooks from Windows functions commonly used by endpoint detection and response, or EDR, products.
Its most concerning option is a Bring Your Own Vulnerable Driver attack. Cruciferra can drop a signed vulnerable driver, then send low-level commands that terminate security processes.
The approach mirrors how trusted drivers can kill EDR, leaving an endpoint far less able to detect what follows.
The crypter also seeks administrator rights, changes registry settings to suppress Windows notifications, and creates persistence after reboot.
It relies on indirect system calls and Import Address Table repair to reduce visibility, reflecting the wider rise of recent EDR evasion framework abuse.
Malware That Vanishes
Cruciferra’s payload protection is designed for variation. Proofpoint found more than 90 encryption routines, many assembled from pieces of known algorithms rather than used unchanged.
Each build can look different to a scanner even when it performs the same job. The final execution step uses a customized form of Process Ghosting.
The malware writes a payload to a temporary file, marks it for deletion, maps it into memory, and allows Windows to remove the disk artifact.
.webp)
It then redirects a suspended legitimate process to the payload and resumes it. The malicious program can keep running even though it was never available on disk in a normal scannable form.
Cruciferra further tries to disguise the deleted backing file when EDR checks memory and interferes with a Windows function that may validate loaded images.
In one campaign, tax-themed messages impersonated the Income Tax Department and led recipients to attacker-controlled ZIP downloads.
Other campaigns used U.S. Social Security Administration notices or guest complaint and bed-bug themes, with shortcut files launching PowerShell to begin the infection chain. It continues to monitor the service’s development and adoption.
Defenders should block vulnerable drivers, keep Windows and endpoint products updated, enable PowerShell logging, and carefully verify unexpected download requests, particularly those using urgent tax or complaint themes.
Indicators of compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| URL | hxxp://sahyteiows.gu.cc |
TA4922 Cruciferra AsyncRAT payload URL, first seen April 28, 2026 |
| URL | hxxp://yicoweytcbtw.gu.cc |
TA4922 Cruciferra AsyncRAT payload URL, first seen April 28, 2026 |
| URL | hxxp://nciyeyrawoe.gu.cc |
TA4922 Cruciferra AsyncRAT payload URL, first seen April 28, 2026 |
| URL | hxxp://lasiduutfe.gu.cc |
TA4922 Cruciferra AsyncRAT payload URL, first seen April 28, 2026 |
| SHA-256 | 3c181f642e24c28602a87be7f195e2f3d1ffa30b37e20f5121d99f88b22ab80e |
Tax-Number52563.zip, TA4922 Cruciferra AsyncRAT |
| URL | hxxp://xkcifgieusr.gu.cc |
TA4922 Cruciferra AsyncRAT payload URL, first seen May 4, 2026 |
| URL | hxxp://viuyeyrwqs.gu.cc |
TA4922 Cruciferra AsyncRAT payload URL, first seen May 4, 2026 |
| URL | hxxp://pmcjsuyraw.gu.cc |
TA4922 Cruciferra AsyncRAT payload URL, first seen May 4, 2026 |
| URL | hxxp://laiwutrencr.gu.cc |
TA4922 Cruciferra AsyncRAT payload URL, first seen May 4, 2026 |
| URL | hxxp://maisytawe.gu.cc |
TA4922 Cruciferra AsyncRAT payload URL, first seen May 4, 2026 |
| URL | hxxp://kawosyetw.gu.cc |
TA4922 Cruciferra AsyncRAT payload URL, first seen May 4, 2026 |
| URL | hxxp://nviuawusye.gu.cc |
TA4922 Cruciferra AsyncRAT payload URL, first seen May 4, 2026 |
| URL | hxxp://faeytrdeaw.gu.cc |
TA4922 Cruciferra AsyncRAT payload URL, first seen May 4, 2026 |
| URL | hxxp://figyuyrqwr.gu.cc |
TA4922 Cruciferra AsyncRAT payload URL, first seen May 4, 2026 |
| URL | hxxp://hfyuayustrv.gu.cc |
TA4922 Cruciferra AsyncRAT payload URL, first seen May 4, 2026 |
| URL | hxxp://jsiruytrawey.gu.cc |
TA4922 Cruciferra AsyncRAT payload URL, first seen May 4, 2026 |
| URL | hxxp://kawuuterta.gu.cc |
TA4922 Cruciferra AsyncRAT payload URL, first seen May 4, 2026 |
| URL | hxxp://nvsieyrrawe.gu.cc |
TA4922 Cruciferra AsyncRAT payload URL, first seen May 4, 2026 |
| SHA-256 | 66dbe675480dc229e5b3ab8ad74207f73486e64e57805074f784bb2e01bcb865 |
Tax-Number809863.zip, TA4922 Cruciferra AsyncRAT |
| URL | hxxp://fuaytrwese.love |
TA4922 Cruciferra AsyncRAT payload URL, first seen May 28, 2026 |
| URL | hxxp://qeuasytua.love |
TA4922 Cruciferra AsyncRAT payload URL, first seen May 28, 2026 |
| URL | hxxp://svuatwea.love |
TA4922 Cruciferra AsyncRAT payload URL, first seen May 28, 2026 |
| URL | hxxp://vusuydryt.love |
TA4922 Cruciferra AsyncRAT payload URL, first seen May 28, 2026 |
| URL | hxxp://xnbscuya.love |
TA4922 Cruciferra AsyncRAT payload URL, first seen May 28, 2026 |
| URL | hxxp://ncduuyese.live |
TA4922 Cruciferra AsyncRAT payload URL, first seen May 28, 2026 |
| URL | hxxp://soakwusya.love |
TA4922 Cruciferra AsyncRAT payload URL, first seen May 28, 2026 |
| URL | hxxp://syfiaydytea.live |
TA4922 Cruciferra AsyncRAT payload URL, first seen May 28, 2026 |
| SHA-256 | a6fb779be35592fb0ff624a8f8e12ab3cafe7bcfc312cd98263814db7fb01e02 |
Tax-Number119863.zip, TA4922 Cruciferra AsyncRAT |
| SHA-256 | 59ad96dd3b4d5f10a5c53bbd465446e52dc7701a4ac633632f762bf1336d3347 |
Tax-Number101863.zip, TA4922 Cruciferra AsyncRAT |
| URL | hxxp://jaiydteds.love |
TA4922 Cruciferra AsyncRAT payload URL, first seen June 1, 2026 |
| URL | hxxp://mksfuuerwo.live |
TA4922 Cruciferra AsyncRAT payload URL, first seen June 1, 2026 |
| URL | hxxp://fiusyevr.live |
TA4922 Cruciferra AsyncRAT payload URL, first seen June 1, 2026 |
| URL | hxxp://lisiutegrm.live |
TA4922 Cruciferra AsyncRAT payload URL, first seen June 1, 2026 |
| URL | hxxp://paiwudyea.love |
TA4922 Cruciferra AsyncRAT payload URL, first seen June 1, 2026 |
| URL | hxxp://xuastyrdqk.love |
TA4922 Cruciferra AsyncRAT payload URL, first seen June 1, 2026 |
| URL | hxxp://sfvxcuvuyte.live |
TA4922 Cruciferra AsyncRAT payload URL, first seen June 1, 2026 |
| URL | hxxp://skdsuyrse.live |
TA4922 Cruciferra AsyncRAT payload URL, first seen June 1, 2026 |
| URL | hxxp://shsauyeet.live |
TA4922 Cruciferra AsyncRAT payload URL, first seen June 1, 2026 |
| SHA-256 | 6dbd6f9f2fa636c16ac4fa81418b68a604424861b9650dd9c4f2b0ba6f67d6ac |
Tax-Number33863.zip, TA4922 Cruciferra AsyncRAT |
| URL | hxxp://almacensantangel.com/wp-includes/assets/YourSSADocuments0000000676152051872026Document0000000676152.rar |
Cruciferra XWorm payload URL |
| Domain | gatuso.duckdns.org |
XWorm command-and-control server |
| SHA-256 | 3f31aee0948d16f8d64bf6bec69a4331099993e502b11bfc56b2c0112024489d |
photo295825092412.zip, Cruciferra zgRAT payload |
| URL | hxxp://digital-magicians.com/photo295825092412.zip?rea623202 |
Cruciferra zgRAT payload URL |
| Domain | 0zbqnac1t4dv2t2wuodv1m.com |
zgRAT command-and-control server |
| IP address and port | 89.34.90.99:56001 |
zgRAT command-and-control server |
| Driver and SHA-256 | Core64.sys / 17aae57cf6255c7eb169bf62ea67376d9708976eb7831f8cdd0ea38bdcb37dc4 |
Vulnerable helper driver used for BYOVD evasion |
| Driver and SHA-256 | GoFlyDrv.sys / 2fdfdd13a0c548bb68c9d5aa8599a9265d4659da3e237fe7a42ac6ac06b9a06a |
Vulnerable helper driver used for BYOVD evasion |
| Driver and SHA-256 | HwOs2Ec.sys / c4e93449453cf67c5d5605bb8f425207a738a242fdb432d720acc32faa74926c |
Vulnerable helper driver used for BYOVD evasion |
| Driver and SHA-256 | LnvMSRIO.sys / c5b1e9aafc8f2b4ab05effc00fd43f3114b9ef1d592a086c952793ac4e299809 |
Vulnerable helper driver used for BYOVD evasion |
| Driver and SHA-256 | MemoryInformer.sys / 7887e919555fb5948c217556ba149392a72982b1bc427d3db779db9dcbf09ee8 |
Vulnerable helper driver used for BYOVD evasion |
| Driver and SHA-256 | NTIOLibX64.sys / 09bedbf7a41e0f8dabe4f41d331db58373ce15b2e9204540873a1884f38bdde1 |
Vulnerable helper driver used for BYOVD evasion |
| Driver and SHA-256 | ProcessMonitorDriver.sys / 5b4f59236a9b950bcd5191b35d19125f60cfb9e1a1e1aa2e4f914b6745dde9df |
Vulnerable helper driver used for BYOVD evasion |
| Driver and SHA-256 | selfprot.sys / c46e907886e2158cbc453e767183aecf07887b5ac8848f19684451883d69f5f0 |
Vulnerable helper driver used for BYOVD evasion |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
! ALERT: 20+ government sites delivered malware to businesses and citizens. See full attack research to check your own exposure
The post This $2,000-a-Month Crypter Can Kill EDR and Make Malware Disappear From Disk appeared first on Cyber Security News.
