New Crypter Evades EDR and Deletes Malware From Disk
Key Takeaways A new crypter service, “Cruciferra,” is being sold for up to $2,000 per month on underground forums. Cruciferra is designed to bypass Endpoint Detection and Response (EDR)...
Key Takeaways
- A new crypter service, “Cruciferra,” is being sold for up to $2,000 per month on underground forums.
- Cruciferra is designed to bypass Endpoint Detection and Response (EDR) solutions and erase malware traces from disk.
- It has been used in numerous campaigns targeting financial, healthcare, government, travel, and hospitality sectors.
- The service deploys various remote access trojans and information stealers, including AsyncRAT, XWorm, and Formbook.
- Defenders should focus on blocking vulnerable drivers, keeping systems updated, enabling PowerShell logging, and scrutinizing unexpected downloads.
A sophisticated new crypter known as Cruciferra is enabling threat actors to circumvent Windows security measures, posing a significant challenge to conventional endpoint protection. This service, offered on a subscription basis for as much as $2,000 monthly, cloaks malicious executables, making them exceedingly difficult for security tools to detect, block, and analyze.
Table Of Content
First observed in the fall of 2025, Cruciferra has been actively advertised across various underground hacker forums. Attackers leveraging this service have employed diverse delivery mechanisms, including deceptive email lures, fraudulent tax portals, embedded links in PDFs, ZIP archives, and virtual hard disk (VHD) files. This broad targeting strategy puts critical sectors such as finance, healthcare, government, travel, and hospitality at elevated risk.
Analysts at Proofpoint have documented dozens of campaigns utilizing Cruciferra. The crypter has been instrumental in delivering a range of potent malware, including remote-access trojans (RATs) and information stealers like AsyncRAT, XWorm, zgRAT, Agent Tesla, Formbook, Remcos, and XLoader.
Proofpoint said in a report that the primary concern is not any single payload, but rather the adaptable nature of the Cruciferra service itself. Its ability to dynamically alter the encapsulation of various malware families renders signature-based detection methods less effective, facilitating widespread compromise across potentially hundreds or thousands of targets.
This $2,000-a-Month Crypter Can Kill EDR
Cruciferra is developed using Mono and primarily operates through DLL side-loading. The infection chain typically begins with victims receiving an archive containing both an executable and a malicious DLL. Upon execution, the Windows operating system inadvertently loads the malicious DLL, initiating the crypter’s operations.
This DLL sideloading technique has been observed in other campaigns, such as those involving AsyncRAT, highlighting the critical need for organizations to exercise extreme caution when encountering unexpected archive files.
Before deploying its final payload, Cruciferra incorporates anti-analysis checks to determine if it is operating within a sandboxed environment or a security analyst’s virtual machine. It employs several stealth techniques, including padding DLLs with benign exported functions, suppressing console windows, and removing monitoring hooks from Windows functions frequently utilized by Endpoint Detection and Response (EDR) solutions.
One of Cruciferra’s most alarming capabilities is its “Bring Your Own Vulnerable Driver” (BYOVD) attack. The crypter can introduce a legitimately signed yet vulnerable driver onto the system, then exploit it to issue low-level commands that effectively terminate active security processes. This tactic mirrors other instances where trusted drivers have been abused to disable EDR products, leaving the compromised endpoint significantly more vulnerable to subsequent attacks.
Beyond EDR evasion, Cruciferra actively seeks elevated administrator privileges, modifies registry settings to disable Windows notifications, and establishes persistence to ensure survival across system reboots. It further enhances its stealth by employing indirect system calls and Import Address Table (IAT) repair, tactics increasingly seen in advanced EDR evasion frameworks.
Malware That Vanishes
Cruciferra’s payload protection mechanisms are designed for extreme variability. Proofpoint researchers identified over 90 distinct encryption routines, many of which are custom-assembled from fragments of established algorithms rather than using them in their original form. This ensures that each crypter build presents a unique signature to scanners, even when delivering identical functionality. The final stage of execution employs a customized variant of Process Ghosting.
In this technique, the malware writes its payload to a temporary file, marks it for immediate deletion, maps it into memory, and then allows Windows to remove the file from disk. Subsequently, it redirects a suspended legitimate process to execute the payload from memory and resumes the process. This allows the malicious program to run without ever existing as a normally scannable artifact on disk. To further obscure its presence, Cruciferra attempts to disguise the deleted backing file during EDR memory inspections and interferes with Windows functions responsible for validating loaded images.
Recent campaigns have utilized diverse social engineering tactics. One notable campaign involved tax-themed messages impersonating the Income Tax Department, directing victims to attacker-controlled ZIP files. Other campaigns leveraged fake U.S. Social Security Administration notices or used themes related to guest complaints and bed bugs, employing shortcut files to launch PowerShell scripts that initiated the infection chain.
Proofpoint continues to monitor the evolution and adoption of this dangerous service. The Indicators of Compromise (IoCs) associated with Cruciferra are provided below for defenders to integrate into their security infrastructure.
What You Should Do
- Block Vulnerable Drivers: Implement policies to prevent the installation and execution of known vulnerable drivers. Regularly audit systems for unauthorized driver installations.
- Keep Systems and EDR Updated: Ensure all operating systems, applications, and EDR solutions are patched and updated to their latest versions to protect against known vulnerabilities and improve detection capabilities.
- Enable PowerShell Logging: Maximize PowerShell logging to capture script block logging, module logging, and transcription. This can help detect and analyze malicious PowerShell activity used in the infection chain.
- Scrutinize Unexpected Downloads: Educate users about the dangers of unsolicited emails and downloads. Emphasize caution, especially with urgent requests related to taxes, complaints, or official notices, which are common lures for Cruciferra campaigns.
- Implement Strong Email Filtering: Utilize advanced email security solutions to detect and block malicious attachments, links, and impersonation attempts before they reach end-users.
- Monitor for DLL Side-Loading: Implement monitoring for unusual DLL loads and process injection attempts, as these are key tactics used by Cruciferra.
| Type | Indicator | Description |
|---|---|---|
| URL | hxxp://sahyteiows.gu.cc |
TA4922 Cruciferra AsyncRAT payload URL, first seen April 28, 2026 |
| URL | hxxp://yicoweytcbtw.gu.cc |
TA4922 Cruciferra AsyncRAT payload URL, first seen April 28, 2026 |
| URL | hxxp://nciyeyrawoe.gu.cc |
TA4922 Cruciferra AsyncRAT payload URL, first seen April 28, 2026 |
| URL | hxxp://lasiduutfe.gu.cc |
TA4922 Cruciferra AsyncRAT payload URL, first seen April 28, 2026 |
| SHA-256 | 3c181f642e24c28602a87be7f195e2f3d1ffa30b37e20f5121d99f88b22ab80e |
Tax-Number52563.zip, TA4922 Cruciferra AsyncRAT |
| URL | hxxp://xkcifgieusr.gu.cc |
TA4922 Cruciferra AsyncRAT payload URL, first seen May 4, 2026 |
| URL | hxxp://viuyeyrwqs.gu.cc |
TA4922 Cruciferra AsyncRAT payload URL, first seen May 4, 2026 |
| URL | hxxp://pmcjsuyraw.gu.cc |
TA4922 Cruciferra AsyncRAT payload URL, first seen May 4, 2026 |
| URL | hxxp://laiwutrencr.gu.cc |
TA4922 Cruciferra AsyncRAT payload URL, first seen May 4, 2026 |
| URL | hxxp://maisytawe.gu.cc |
TA4922 Cruciferra AsyncRAT payload URL, first seen May 4, 2026 |
| URL | hxxp://kawosyetw.gu.cc |
TA4922 Cruciferra AsyncRAT payload URL, first seen May 4, 2026 |
| URL | hxxp://nviuawusye.gu.cc |
TA4922 Cruciferra AsyncRAT payload URL, first seen May 4, 2026 |
| URL | hxxp://faeytrdeaw.gu.cc |
TA4922 Cruciferra AsyncRAT payload URL, first seen May 4, 2026 |
| URL | hxxp://figyuyrqwr.gu.cc |
TA4922 Cruciferra AsyncRAT payload URL, first seen May 4, 2026 |
| URL | hxxp://hfyuayustrv.gu.cc |
TA4922 Cruciferra AsyncRAT payload URL, first seen May 4, 2026 |
| URL | hxxp://jsiruytrawey.gu.cc |
TA4922 Cruciferra AsyncRAT payload URL, first seen May 4, 2026 |
| URL | hxxp://kawuuterta.gu.cc |
TA4922 Cruciferra AsyncRAT payload URL, first seen May 4, 2026 |
| URL | hxxp://nvsieyrrawe.gu.cc |
TA4922 Cruciferra AsyncRAT payload URL, first seen May 4, 2026 |
| SHA-256 | 66dbe675480dc229e5b3ab8ad74207f73486e64e57805074f784bb2e01bcb865 |
Tax-Number809863.zip, TA4922 Cruciferra AsyncRAT |
| URL | hxxp://fuaytrwese.love |
TA4922 Cruciferra AsyncRAT payload URL, first seen May 28, 2026 |
| URL | hxxp://qeuasytua.love |
TA4922 Cruciferra AsyncRAT payload URL, first seen May 28, 2026 |
| URL | hxxp://svuatwea.love |
TA4922 Cruciferra AsyncRAT payload URL, first seen May 28, 2026 |
| URL | hxxp://vusuydryt.love |
TA4922 Cruciferra AsyncRAT payload URL, first seen May 28, 2026 |
| URL | hxxp://xnbscuya.love |
TA4922 Cruciferra AsyncRAT payload URL, first seen May 28, 2026 |
| URL | hxxp://ncduuyese.live |
TA4922 Cruciferra AsyncRAT payload URL, first seen May 28, 2026 |
| URL | hxxp://soakwusya.love |
TA4922 Cruciferra AsyncRAT payload URL, first seen May 28, 2026 |
| URL | hxxp://syfiaydytea.live |
TA4922 Cruciferra AsyncRAT payload URL, first seen May 28, 2026 |
| SHA-256 | a6fb779be35592fb0ff624a8f8e12ab3cafe7bcfc312cd98263814db7fb01e02 |
Tax-Number119863.zip, TA4922 Cruciferra AsyncRAT |
| SHA-256 | 59ad96dd3b4d5f10a5c53bbd465446e52dc7701a4ac633632f762bf1336d3347 |
Tax-Number101863.zip, TA4922 Cruciferra AsyncRAT |
| URL | hxxp://jaiydteds.love |
TA4922 Cruciferra AsyncRAT payload URL, first seen June 1, 2026 |
| URL | hxxp://mksfuuerwo.live |
TA4922 Cruciferra AsyncRAT payload URL, first seen June 1, 2026 |
| URL | hxxp://fiusyevr.live |
TA4922 Cruciferra AsyncRAT payload URL, first seen June 1, 2026 |
| URL | hxxp://lisiutegrm.live |
TA4922 Cruciferra AsyncRAT payload URL, first seen June 1, 2026 |
| URL | hxxp://paiwudyea.love |
TA4922 Cruciferra AsyncRAT payload URL, first seen June 1, 2026 |
| URL | hxxp://xuastyrdqk.love |
TA4922 Cruciferra AsyncRAT payload URL, first seen June 1, 2026 |
| URL | hxxp://sfvxcuvuyte.live |
TA4922 Cruciferra AsyncRAT payload URL, first seen June 1, 2026 |
| URL | hxxp://skdsuyrse.live |
TA4922 Cruciferra AsyncRAT payload URL, first seen June 1, 2026 |
| URL | hxxp://shsauyeet.live |
TA4922 Cruciferra AsyncRAT payload URL, first seen June 1, 2026 |
| SHA-256 | 6dbd6f9f2fa636c16ac4fa81418b68a604424861b9650dd9c4f2b0ba6f67d6ac |
Tax-Number33863.zip, TA4922 Cruciferra AsyncRAT |
| URL | hxxp://almacensantangel.com/wp-includes/assets/YourSSADocuments0000000676152051872026Document0000000676152.rar |
Cruciferra XWorm payload URL |
| Domain | gatuso.duckdns.org |
XWorm command-and-control server |
| SHA-256 | 3f31aee0948d16f8d64bf6bec69a4331099993e502b11bfc56b2c0112024489d |
photo295825092412.zip, Cruciferra zgRAT payload |
| URL | hxxp://digital-magicians.com/photo295825092412.zip?rea623202 |
Cruciferra zgRAT payload URL |
| Domain | 0zbqnac1t4dv2t2wuodv1m.com |
zgRAT command-and-control server |
| IP address and port | 89.34.90.99:56001 |
zgRAT command-and-control server |
| Driver and SHA-256 | Core64.sys / 17aae57cf6255c7eb169bf62ea67376d9708976eb7831f8cdd0ea38bdcb37dc4 |
Vulnerable helper driver used for BYOVD evasion |
| Driver and SHA-256 | GoFlyDrv.sys / 2fdfdd13a0c548bb68c9d5aa8599a9265d4659da3e237fe7a42ac6ac06b9a06a |
Vulnerable helper driver used for BYOVD evasion |
| Driver and SHA-256 | HwOs2Ec.sys / c4e93449453cf67c5d5605bb8f425207a738a242fdb432d720acc32faa74926c |
Vulnerable helper driver used for BYOVD evasion |
| Driver and SHA-256 | LnvMSRIO.sys / c5b1e9aafc8f2b4ab05effc00fd43f3114b9ef1d592a086c952793ac4e299809 |
Vulnerable helper driver used for BYOVD evasion |
| Driver and SHA-256 | MemoryInformer.sys / 7887e919555fb5948c217556ba149392a72982b1bc427d3db779db9dcbf09ee8 |
Vulnerable helper driver used for BYOVD evasion |
| Driver and SHA-256 | NTIOLibX64.sys / 09bedbf7a41e0f8dabe4f41d331db58373ce15b2e9204540873a1884f38bdde1 |
Vulnerable helper driver used for BYOVD evasion |
| Driver and SHA-256 | ProcessMonitorDriver.sys / 5b4f59236a9b950bcd5191b35d19125f60cfb9e1a1e1aa2e4f914b6745dde9df |
Vulnerable helper driver used for BYOVD evasion |
| Driver and SHA-256 | selfprot.sys / c46e907886e2158cbc453e767183aecf07887b5ac8848f19684451883d69f5f0 |
Vulnerable helper driver used for BYOVD evasion |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.