The real break is that evasive malware is no longer a one-off trick tied to one RAT family. Cruciferra packages the hiding layer itself, so different crews can keep swapping payloads while the wrapper stays built to evade EDR and static hunting.
Proofpoint says Cruciferra is being sold as a subscription service and is already tied to dozens of campaigns delivering commodity RATs and keyloggers. The service uses DLL side-loading, process ghosting, more than 90 custom ciphers, and vulnerable signed drivers to mute telemetry and make each sample look different.
That shifts the defensive problem upstream. Hunting hashes and family names will miss a shared evasion layer that is being reused, resold, and kept under active development.