Skip to content
Malware

This $2,000-a-Month Crypter Can Kill EDR and Make Malware Disappear From Disk

A criminal service called Cruciferra is giving malware operators a way to slip past Windows defenses. Sold as a subscription crypter for as much as $2,000 a month, it wraps malicious programs so security tools struggle to inspect, block, and trace them. The service has been active since fall 2025 an...

· Jul 22, 2026 · 7 min read · 👁 4 views
This $2,000-a-Month Crypter Can Kill EDR and Make Malware Disappear From Disk

A criminal service called Cruciferra is giving malware operators a way to slip past Windows defenses.

Sold as a subscription crypter for as much as $2,000 a month, it wraps malicious programs so security tools struggle to inspect, block, and trace them.

The service has been active since fall 2025 and is advertised on underground forums.

Attackers have used email lures, fake tax portals, PDF links, ZIP archives, and virtual hard disk files to deliver it, putting financial, healthcare, government, travel, and hospitality organizations at risk.

Analysts at Proofpoint identified Cruciferra in dozens of campaigns. The tool has delivered remote-access trojans and information stealers, including AsyncRAT, XWorm, zgRAT, Agent Tesla, Formbook, Remcos, and XLoader.

A public advertisement and notice of Cruciferra (from exploit[.]in) (Source - Proofpoint)
A public advertisement and notice of Cruciferra (from exploit[.]in) (Source – Proofpoint)

Proofpoint said in a report shared with Cyber Security News (CSN) the immediate danger is not one payload, but the service behind it.

Buyers can conceal different malware families behind changing code, making signature-based detection less dependable and helping campaigns reach hundreds or thousands of targets.

This $2,000-a-Month Crypter Can Kill EDR

Cruciferra is written in Mono and runs through DLL side-loading. Victims receive an archive with an executable and DLL; when launched, Windows loads the malicious DLL and starts the crypter.

That pattern also appeared in an AsyncRAT DLL sideloading campaign, reinforcing why unexpected archives need careful scrutiny.

Before releasing its payload, Cruciferra checks whether it is running in a sandbox or analyst virtual machine.

Fake Income Tax Department portal used to host the ZIP file which initiates the Cruciferra infection chain (Source - Proofpoint)
Fake Income Tax Department portal used to host the ZIP file which initiates the Cruciferra infection chain (Source – Proofpoint)

It pads DLLs with harmless exported functions, hides console windows, and removes monitoring hooks from Windows functions commonly used by endpoint detection and response, or EDR, products.

Its most concerning option is a Bring Your Own Vulnerable Driver attack. Cruciferra can drop a signed vulnerable driver, then send low-level commands that terminate security processes.

The approach mirrors how trusted drivers can kill EDR, leaving an endpoint far less able to detect what follows.

The crypter also seeks administrator rights, changes registry settings to suppress Windows notifications, and creates persistence after reboot.

It relies on indirect system calls and Import Address Table repair to reduce visibility, reflecting the wider rise of recent EDR evasion framework abuse.

Malware That Vanishes

Cruciferra’s payload protection is designed for variation. Proofpoint found more than 90 encryption routines, many assembled from pieces of known algorithms rather than used unchanged.

Each build can look different to a scanner even when it performs the same job. The final execution step uses a customized form of Process Ghosting.

The malware writes a payload to a temporary file, marks it for deletion, maps it into memory, and allows Windows to remove the disk artifact.

Fraudulent SSA emails (Source - Proofpoint)
Fraudulent SSA emails (Source – Proofpoint)

It then redirects a suspended legitimate process to the payload and resumes it. The malicious program can keep running even though it was never available on disk in a normal scannable form.

Cruciferra further tries to disguise the deleted backing file when EDR checks memory and interferes with a Windows function that may validate loaded images.

In one campaign, tax-themed messages impersonated the Income Tax Department and led recipients to attacker-controlled ZIP downloads.

Other campaigns used U.S. Social Security Administration notices or guest complaint and bed-bug themes, with shortcut files launching PowerShell to begin the infection chain. It continues to monitor the service’s development and adoption.

Defenders should block vulnerable drivers, keep Windows and endpoint products updated, enable PowerShell logging, and carefully verify unexpected download requests, particularly those using urgent tax or complaint themes.

Indicators of compromise (IoCs):-

TypeIndicatorDescription
URLhxxp://sahyteiows.gu.ccTA4922 Cruciferra AsyncRAT payload URL, first seen April 28, 2026
URLhxxp://yicoweytcbtw.gu.ccTA4922 Cruciferra AsyncRAT payload URL, first seen April 28, 2026
URLhxxp://nciyeyrawoe.gu.ccTA4922 Cruciferra AsyncRAT payload URL, first seen April 28, 2026
URLhxxp://lasiduutfe.gu.ccTA4922 Cruciferra AsyncRAT payload URL, first seen April 28, 2026
SHA-2563c181f642e24c28602a87be7f195e2f3d1ffa30b37e20f5121d99f88b22ab80eTax-Number52563.zip, TA4922 Cruciferra AsyncRAT
URLhxxp://xkcifgieusr.gu.ccTA4922 Cruciferra AsyncRAT payload URL, first seen May 4, 2026
URLhxxp://viuyeyrwqs.gu.ccTA4922 Cruciferra AsyncRAT payload URL, first seen May 4, 2026
URLhxxp://pmcjsuyraw.gu.ccTA4922 Cruciferra AsyncRAT payload URL, first seen May 4, 2026
URLhxxp://laiwutrencr.gu.ccTA4922 Cruciferra AsyncRAT payload URL, first seen May 4, 2026
URLhxxp://maisytawe.gu.ccTA4922 Cruciferra AsyncRAT payload URL, first seen May 4, 2026
URLhxxp://kawosyetw.gu.ccTA4922 Cruciferra AsyncRAT payload URL, first seen May 4, 2026
URLhxxp://nviuawusye.gu.ccTA4922 Cruciferra AsyncRAT payload URL, first seen May 4, 2026
URLhxxp://faeytrdeaw.gu.ccTA4922 Cruciferra AsyncRAT payload URL, first seen May 4, 2026
URLhxxp://figyuyrqwr.gu.ccTA4922 Cruciferra AsyncRAT payload URL, first seen May 4, 2026
URLhxxp://hfyuayustrv.gu.ccTA4922 Cruciferra AsyncRAT payload URL, first seen May 4, 2026
URLhxxp://jsiruytrawey.gu.ccTA4922 Cruciferra AsyncRAT payload URL, first seen May 4, 2026
URLhxxp://kawuuterta.gu.ccTA4922 Cruciferra AsyncRAT payload URL, first seen May 4, 2026
URLhxxp://nvsieyrrawe.gu.ccTA4922 Cruciferra AsyncRAT payload URL, first seen May 4, 2026
SHA-25666dbe675480dc229e5b3ab8ad74207f73486e64e57805074f784bb2e01bcb865Tax-Number809863.zip, TA4922 Cruciferra AsyncRAT
URLhxxp://fuaytrwese.loveTA4922 Cruciferra AsyncRAT payload URL, first seen May 28, 2026
URLhxxp://qeuasytua.loveTA4922 Cruciferra AsyncRAT payload URL, first seen May 28, 2026
URLhxxp://svuatwea.loveTA4922 Cruciferra AsyncRAT payload URL, first seen May 28, 2026
URLhxxp://vusuydryt.loveTA4922 Cruciferra AsyncRAT payload URL, first seen May 28, 2026
URLhxxp://xnbscuya.loveTA4922 Cruciferra AsyncRAT payload URL, first seen May 28, 2026
URLhxxp://ncduuyese.liveTA4922 Cruciferra AsyncRAT payload URL, first seen May 28, 2026
URLhxxp://soakwusya.loveTA4922 Cruciferra AsyncRAT payload URL, first seen May 28, 2026
URLhxxp://syfiaydytea.liveTA4922 Cruciferra AsyncRAT payload URL, first seen May 28, 2026
SHA-256a6fb779be35592fb0ff624a8f8e12ab3cafe7bcfc312cd98263814db7fb01e02Tax-Number119863.zip, TA4922 Cruciferra AsyncRAT
SHA-25659ad96dd3b4d5f10a5c53bbd465446e52dc7701a4ac633632f762bf1336d3347Tax-Number101863.zip, TA4922 Cruciferra AsyncRAT
URLhxxp://jaiydteds.loveTA4922 Cruciferra AsyncRAT payload URL, first seen June 1, 2026
URLhxxp://mksfuuerwo.liveTA4922 Cruciferra AsyncRAT payload URL, first seen June 1, 2026
URLhxxp://fiusyevr.liveTA4922 Cruciferra AsyncRAT payload URL, first seen June 1, 2026
URLhxxp://lisiutegrm.liveTA4922 Cruciferra AsyncRAT payload URL, first seen June 1, 2026
URLhxxp://paiwudyea.loveTA4922 Cruciferra AsyncRAT payload URL, first seen June 1, 2026
URLhxxp://xuastyrdqk.loveTA4922 Cruciferra AsyncRAT payload URL, first seen June 1, 2026
URLhxxp://sfvxcuvuyte.liveTA4922 Cruciferra AsyncRAT payload URL, first seen June 1, 2026
URLhxxp://skdsuyrse.liveTA4922 Cruciferra AsyncRAT payload URL, first seen June 1, 2026
URLhxxp://shsauyeet.liveTA4922 Cruciferra AsyncRAT payload URL, first seen June 1, 2026
SHA-2566dbd6f9f2fa636c16ac4fa81418b68a604424861b9650dd9c4f2b0ba6f67d6acTax-Number33863.zip, TA4922 Cruciferra AsyncRAT
URLhxxp://almacensantangel.com/wp-includes/assets/YourSSADocuments0000000676152051872026Document0000000676152.rarCruciferra XWorm payload URL
Domaingatuso.duckdns.orgXWorm command-and-control server
SHA-2563f31aee0948d16f8d64bf6bec69a4331099993e502b11bfc56b2c0112024489dphoto295825092412.zip, Cruciferra zgRAT payload
URLhxxp://digital-magicians.com/photo295825092412.zip?rea623202Cruciferra zgRAT payload URL
Domain0zbqnac1t4dv2t2wuodv1m.comzgRAT command-and-control server
IP address and port89.34.90.99:56001zgRAT command-and-control server
Driver and SHA-256Core64.sys / 17aae57cf6255c7eb169bf62ea67376d9708976eb7831f8cdd0ea38bdcb37dc4Vulnerable helper driver used for BYOVD evasion
Driver and SHA-256GoFlyDrv.sys / 2fdfdd13a0c548bb68c9d5aa8599a9265d4659da3e237fe7a42ac6ac06b9a06aVulnerable helper driver used for BYOVD evasion
Driver and SHA-256HwOs2Ec.sys / c4e93449453cf67c5d5605bb8f425207a738a242fdb432d720acc32faa74926cVulnerable helper driver used for BYOVD evasion
Driver and SHA-256LnvMSRIO.sys / c5b1e9aafc8f2b4ab05effc00fd43f3114b9ef1d592a086c952793ac4e299809Vulnerable helper driver used for BYOVD evasion
Driver and SHA-256MemoryInformer.sys / 7887e919555fb5948c217556ba149392a72982b1bc427d3db779db9dcbf09ee8Vulnerable helper driver used for BYOVD evasion
Driver and SHA-256NTIOLibX64.sys / 09bedbf7a41e0f8dabe4f41d331db58373ce15b2e9204540873a1884f38bdde1Vulnerable helper driver used for BYOVD evasion
Driver and SHA-256ProcessMonitorDriver.sys / 5b4f59236a9b950bcd5191b35d19125f60cfb9e1a1e1aa2e4f914b6745dde9dfVulnerable helper driver used for BYOVD evasion
Driver and SHA-256selfprot.sys / c46e907886e2158cbc453e767183aecf07887b5ac8848f19684451883d69f5f0Vulnerable helper driver used for BYOVD evasion

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Source: CybersecurityNews.com

Follow ShomoySoft for more: Follow on Facebook

💬 Comments (0)

Login to join the discussion.

No comments yet. Be the first!

Recommended for you