Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Fake Game Apps Deliver Multi-Stage Infostealers, Steal Crypto and Passwords
July 21, 2026
Qilin Ransomware Claims 1,358 Victims, Global Attacks Soar
July 21, 2026
Hackers Hijack Government Websites to Deliver Malware via Trusted Links
July 21, 2026
Home/CyberSecurity News/New Crypter Evades EDR and Deletes Malware From Disk
CyberSecurity News

New Crypter Evades EDR and Deletes Malware From Disk

Key Takeaways A new crypter service, “Cruciferra,” is being sold for up to $2,000 per month on underground forums. Cruciferra is designed to bypass Endpoint Detection and Response (EDR)...

David kimber
David kimber
July 21, 2026 6 Min Read
5 0

Key Takeaways

  • A new crypter service, “Cruciferra,” is being sold for up to $2,000 per month on underground forums.
  • Cruciferra is designed to bypass Endpoint Detection and Response (EDR) solutions and erase malware traces from disk.
  • It has been used in numerous campaigns targeting financial, healthcare, government, travel, and hospitality sectors.
  • The service deploys various remote access trojans and information stealers, including AsyncRAT, XWorm, and Formbook.
  • Defenders should focus on blocking vulnerable drivers, keeping systems updated, enabling PowerShell logging, and scrutinizing unexpected downloads.

A sophisticated new crypter known as Cruciferra is enabling threat actors to circumvent Windows security measures, posing a significant challenge to conventional endpoint protection. This service, offered on a subscription basis for as much as $2,000 monthly, cloaks malicious executables, making them exceedingly difficult for security tools to detect, block, and analyze.

Table Of Content

  • Key Takeaways
  • This $2,000-a-Month Crypter Can Kill EDR
  • Malware That Vanishes
  • What You Should Do

First observed in the fall of 2025, Cruciferra has been actively advertised across various underground hacker forums. Attackers leveraging this service have employed diverse delivery mechanisms, including deceptive email lures, fraudulent tax portals, embedded links in PDFs, ZIP archives, and virtual hard disk (VHD) files. This broad targeting strategy puts critical sectors such as finance, healthcare, government, travel, and hospitality at elevated risk.

Analysts at Proofpoint have documented dozens of campaigns utilizing Cruciferra. The crypter has been instrumental in delivering a range of potent malware, including remote-access trojans (RATs) and information stealers like AsyncRAT, XWorm, zgRAT, Agent Tesla, Formbook, Remcos, and XLoader.

Proofpoint said in a report that the primary concern is not any single payload, but rather the adaptable nature of the Cruciferra service itself. Its ability to dynamically alter the encapsulation of various malware families renders signature-based detection methods less effective, facilitating widespread compromise across potentially hundreds or thousands of targets.

This $2,000-a-Month Crypter Can Kill EDR

Cruciferra is developed using Mono and primarily operates through DLL side-loading. The infection chain typically begins with victims receiving an archive containing both an executable and a malicious DLL. Upon execution, the Windows operating system inadvertently loads the malicious DLL, initiating the crypter’s operations.

This DLL sideloading technique has been observed in other campaigns, such as those involving AsyncRAT, highlighting the critical need for organizations to exercise extreme caution when encountering unexpected archive files.

Before deploying its final payload, Cruciferra incorporates anti-analysis checks to determine if it is operating within a sandboxed environment or a security analyst’s virtual machine. It employs several stealth techniques, including padding DLLs with benign exported functions, suppressing console windows, and removing monitoring hooks from Windows functions frequently utilized by Endpoint Detection and Response (EDR) solutions.

One of Cruciferra’s most alarming capabilities is its “Bring Your Own Vulnerable Driver” (BYOVD) attack. The crypter can introduce a legitimately signed yet vulnerable driver onto the system, then exploit it to issue low-level commands that effectively terminate active security processes. This tactic mirrors other instances where trusted drivers have been abused to disable EDR products, leaving the compromised endpoint significantly more vulnerable to subsequent attacks.

Beyond EDR evasion, Cruciferra actively seeks elevated administrator privileges, modifies registry settings to disable Windows notifications, and establishes persistence to ensure survival across system reboots. It further enhances its stealth by employing indirect system calls and Import Address Table (IAT) repair, tactics increasingly seen in advanced EDR evasion frameworks.

Malware That Vanishes

Cruciferra’s payload protection mechanisms are designed for extreme variability. Proofpoint researchers identified over 90 distinct encryption routines, many of which are custom-assembled from fragments of established algorithms rather than using them in their original form. This ensures that each crypter build presents a unique signature to scanners, even when delivering identical functionality. The final stage of execution employs a customized variant of Process Ghosting.

In this technique, the malware writes its payload to a temporary file, marks it for immediate deletion, maps it into memory, and then allows Windows to remove the file from disk. Subsequently, it redirects a suspended legitimate process to execute the payload from memory and resumes the process. This allows the malicious program to run without ever existing as a normally scannable artifact on disk. To further obscure its presence, Cruciferra attempts to disguise the deleted backing file during EDR memory inspections and interferes with Windows functions responsible for validating loaded images.

Recent campaigns have utilized diverse social engineering tactics. One notable campaign involved tax-themed messages impersonating the Income Tax Department, directing victims to attacker-controlled ZIP files. Other campaigns leveraged fake U.S. Social Security Administration notices or used themes related to guest complaints and bed bugs, employing shortcut files to launch PowerShell scripts that initiated the infection chain.

Proofpoint continues to monitor the evolution and adoption of this dangerous service. The Indicators of Compromise (IoCs) associated with Cruciferra are provided below for defenders to integrate into their security infrastructure.

What You Should Do

  • Block Vulnerable Drivers: Implement policies to prevent the installation and execution of known vulnerable drivers. Regularly audit systems for unauthorized driver installations.
  • Keep Systems and EDR Updated: Ensure all operating systems, applications, and EDR solutions are patched and updated to their latest versions to protect against known vulnerabilities and improve detection capabilities.
  • Enable PowerShell Logging: Maximize PowerShell logging to capture script block logging, module logging, and transcription. This can help detect and analyze malicious PowerShell activity used in the infection chain.
  • Scrutinize Unexpected Downloads: Educate users about the dangers of unsolicited emails and downloads. Emphasize caution, especially with urgent requests related to taxes, complaints, or official notices, which are common lures for Cruciferra campaigns.
  • Implement Strong Email Filtering: Utilize advanced email security solutions to detect and block malicious attachments, links, and impersonation attempts before they reach end-users.
  • Monitor for DLL Side-Loading: Implement monitoring for unusual DLL loads and process injection attempts, as these are key tactics used by Cruciferra.
Type Indicator Description
URL hxxp://sahyteiows.gu.cc TA4922 Cruciferra AsyncRAT payload URL, first seen April 28, 2026
URL hxxp://yicoweytcbtw.gu.cc TA4922 Cruciferra AsyncRAT payload URL, first seen April 28, 2026
URL hxxp://nciyeyrawoe.gu.cc TA4922 Cruciferra AsyncRAT payload URL, first seen April 28, 2026
URL hxxp://lasiduutfe.gu.cc TA4922 Cruciferra AsyncRAT payload URL, first seen April 28, 2026
SHA-256 3c181f642e24c28602a87be7f195e2f3d1ffa30b37e20f5121d99f88b22ab80e Tax-Number52563.zip, TA4922 Cruciferra AsyncRAT
URL hxxp://xkcifgieusr.gu.cc TA4922 Cruciferra AsyncRAT payload URL, first seen May 4, 2026
URL hxxp://viuyeyrwqs.gu.cc TA4922 Cruciferra AsyncRAT payload URL, first seen May 4, 2026
URL hxxp://pmcjsuyraw.gu.cc TA4922 Cruciferra AsyncRAT payload URL, first seen May 4, 2026
URL hxxp://laiwutrencr.gu.cc TA4922 Cruciferra AsyncRAT payload URL, first seen May 4, 2026
URL hxxp://maisytawe.gu.cc TA4922 Cruciferra AsyncRAT payload URL, first seen May 4, 2026
URL hxxp://kawosyetw.gu.cc TA4922 Cruciferra AsyncRAT payload URL, first seen May 4, 2026
URL hxxp://nviuawusye.gu.cc TA4922 Cruciferra AsyncRAT payload URL, first seen May 4, 2026
URL hxxp://faeytrdeaw.gu.cc TA4922 Cruciferra AsyncRAT payload URL, first seen May 4, 2026
URL hxxp://figyuyrqwr.gu.cc TA4922 Cruciferra AsyncRAT payload URL, first seen May 4, 2026
URL hxxp://hfyuayustrv.gu.cc TA4922 Cruciferra AsyncRAT payload URL, first seen May 4, 2026
URL hxxp://jsiruytrawey.gu.cc TA4922 Cruciferra AsyncRAT payload URL, first seen May 4, 2026
URL hxxp://kawuuterta.gu.cc TA4922 Cruciferra AsyncRAT payload URL, first seen May 4, 2026
URL hxxp://nvsieyrrawe.gu.cc TA4922 Cruciferra AsyncRAT payload URL, first seen May 4, 2026
SHA-256 66dbe675480dc229e5b3ab8ad74207f73486e64e57805074f784bb2e01bcb865 Tax-Number809863.zip, TA4922 Cruciferra AsyncRAT
URL hxxp://fuaytrwese.love TA4922 Cruciferra AsyncRAT payload URL, first seen May 28, 2026
URL hxxp://qeuasytua.love TA4922 Cruciferra AsyncRAT payload URL, first seen May 28, 2026
URL hxxp://svuatwea.love TA4922 Cruciferra AsyncRAT payload URL, first seen May 28, 2026
URL hxxp://vusuydryt.love TA4922 Cruciferra AsyncRAT payload URL, first seen May 28, 2026
URL hxxp://xnbscuya.love TA4922 Cruciferra AsyncRAT payload URL, first seen May 28, 2026
URL hxxp://ncduuyese.live TA4922 Cruciferra AsyncRAT payload URL, first seen May 28, 2026
URL hxxp://soakwusya.love TA4922 Cruciferra AsyncRAT payload URL, first seen May 28, 2026
URL hxxp://syfiaydytea.live TA4922 Cruciferra AsyncRAT payload URL, first seen May 28, 2026
SHA-256 a6fb779be35592fb0ff624a8f8e12ab3cafe7bcfc312cd98263814db7fb01e02 Tax-Number119863.zip, TA4922 Cruciferra AsyncRAT
SHA-256 59ad96dd3b4d5f10a5c53bbd465446e52dc7701a4ac633632f762bf1336d3347 Tax-Number101863.zip, TA4922 Cruciferra AsyncRAT
URL hxxp://jaiydteds.love TA4922 Cruciferra AsyncRAT payload URL, first seen June 1, 2026
URL hxxp://mksfuuerwo.live TA4922 Cruciferra AsyncRAT payload URL, first seen June 1, 2026
URL hxxp://fiusyevr.live TA4922 Cruciferra AsyncRAT payload URL, first seen June 1, 2026
URL hxxp://lisiutegrm.live TA4922 Cruciferra AsyncRAT payload URL, first seen June 1, 2026
URL hxxp://paiwudyea.love TA4922 Cruciferra AsyncRAT payload URL, first seen June 1, 2026
URL hxxp://xuastyrdqk.love TA4922 Cruciferra AsyncRAT payload URL, first seen June 1, 2026
URL hxxp://sfvxcuvuyte.live TA4922 Cruciferra AsyncRAT payload URL, first seen June 1, 2026
URL hxxp://skdsuyrse.live TA4922 Cruciferra AsyncRAT payload URL, first seen June 1, 2026
URL hxxp://shsauyeet.live TA4922 Cruciferra AsyncRAT payload URL, first seen June 1, 2026
SHA-256 6dbd6f9f2fa636c16ac4fa81418b68a604424861b9650dd9c4f2b0ba6f67d6ac Tax-Number33863.zip, TA4922 Cruciferra AsyncRAT
URL hxxp://almacensantangel.com/wp-includes/assets/YourSSADocuments0000000676152051872026Document0000000676152.rar Cruciferra XWorm payload URL
Domain gatuso.duckdns.org XWorm command-and-control server
SHA-256 3f31aee0948d16f8d64bf6bec69a4331099993e502b11bfc56b2c0112024489d photo295825092412.zip, Cruciferra zgRAT payload
URL hxxp://digital-magicians.com/photo295825092412.zip?rea623202 Cruciferra zgRAT payload URL
Domain 0zbqnac1t4dv2t2wuodv1m.com zgRAT command-and-control server
IP address and port 89.34.90.99:56001 zgRAT command-and-control server
Driver and SHA-256 Core64.sys / 17aae57cf6255c7eb169bf62ea67376d9708976eb7831f8cdd0ea38bdcb37dc4 Vulnerable helper driver used for BYOVD evasion
Driver and SHA-256 GoFlyDrv.sys / 2fdfdd13a0c548bb68c9d5aa8599a9265d4659da3e237fe7a42ac6ac06b9a06a Vulnerable helper driver used for BYOVD evasion
Driver and SHA-256 HwOs2Ec.sys / c4e93449453cf67c5d5605bb8f425207a738a242fdb432d720acc32faa74926c Vulnerable helper driver used for BYOVD evasion
Driver and SHA-256 LnvMSRIO.sys / c5b1e9aafc8f2b4ab05effc00fd43f3114b9ef1d592a086c952793ac4e299809 Vulnerable helper driver used for BYOVD evasion
Driver and SHA-256 MemoryInformer.sys / 7887e919555fb5948c217556ba149392a72982b1bc427d3db779db9dcbf09ee8 Vulnerable helper driver used for BYOVD evasion
Driver and SHA-256 NTIOLibX64.sys / 09bedbf7a41e0f8dabe4f41d331db58373ce15b2e9204540873a1884f38bdde1 Vulnerable helper driver used for BYOVD evasion
Driver and SHA-256 ProcessMonitorDriver.sys / 5b4f59236a9b950bcd5191b35d19125f60cfb9e1a1e1aa2e4f914b6745dde9df Vulnerable helper driver used for BYOVD evasion
Driver and SHA-256 selfprot.sys / c46e907886e2158cbc453e767183aecf07887b5ac8848f19684451883d69f5f0 Vulnerable helper driver used for BYOVD evasion

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackExploitMalwareSecurityThreat

Share Article

David kimber

David kimber

David is a penetration tester turned security journalist with expertise in mobile security, IoT vulnerabilities, and exploit development. As an OSCP-certified security professional, David brings hands-on technical experience to his reporting on vulnerabilities and security research. His articles often feature detailed technical analysis of exploits and provide actionable defense recommendations. David maintains an active presence in the security research community and has contributed to multiple open-source security tools.

Previous Post

Google Gemini 3.5 Flash AI Speeds Vulnerability Detection and Patching

Next Post

Hackers Hijack Government Websites to Deliver Malware via Trusted Links

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Trump AI Safety Chief Resigns After Three Months
July 21, 2026
APT42 Targets Officials with AI Phishing, TAMECAT Malware
July 21, 2026
Critical GitHub Actions Flaw Backdoors AsyncAPI npm Packages with Miasma RAT
July 21, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
David kimber
David kimber
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us