Malware · 49 days ago
The real break is that evasive malware is no longer a one-off trick tied to one RAT family. Cruciferra packages the hiding layer itself, so different crews can keep swapping payloads while the wrapper stays built to evade EDR and static hunting.
Proofpoint says Cruciferra is being sold as a subscription service and is already tied to dozens of campaigns delivering commodity RATs and keyloggers. The service uses DLL side-loading, process ghosting, more than 90 custom ciphers, and vulnerable signed drivers to mute telemetry and make each sample look different.
That shifts the defensive problem upstream. Hunting hashes and family names will miss a shared evasion layer that is being reused, resold, and kept under active development.
2 sources covering this story
Cruciferra Crypter Uses BYOVD and Process Ghosting to Hide Windows Malware
Cruciferra uses BYOVD, API unhooking, and Process Ghosting to hide RAT and stealer payloads delivered through phishing campaigns
Cruciferra Crypter Uses Process Ghosting to Evade Detection
Cruciferra crypter used process ghosting and 90 custom ciphers to hide payloads for multiple actors
Part of the PlainSec briefing for 2026-07-28