Security News

Cybersecurity news aggregator

HIGH Attacks SC Media

Sophisticated crypter service Cruciferra evades detection with advanced techniques

The Cruciferra crypter service employs advanced evasion techniques like process ghosting, kernel-driver abuse, and EDR unhooking to cloak commodity malware such as AsyncRAT and Agent Tesla. It operates as a subscription-based service for multiple criminal groups, delivering payloads via methods like DLL side-loading and using over 90 encryption routines. Observed campaigns have primarily targeted financial services, healthcare, and government sectors through impersonation attacks.
Read Full Article →

Threat Intelligence Sophisticated crypter service Cruciferra evades detection with advanced techniques July 21, 2026 Share By SC Staff (Adobe Stock) A sophisticated crypter service known as Cruciferra has been documented employing advanced techniques like process ghosting and kernel-driver abuse to cloak commodity malware. This service is being utilized by multiple, unrelated cyber-criminal groups to deliver a variety of malicious payloads, according to a recent report by Infosecurity Magazine. Cruciferra, first offered for sale in autumn 2025, underpins dozens of campaigns delivering malware such as AsyncRAT, Agent Tesla, and Remcos. The service offers tiered access ranging from $450 to $2,000 per month and is actively developed, with new samples appearing frequently. Attack methods include DLL side-loading, where a legitimate executable is paired with a malicious DLL. Before execution, Cruciferra unhooks endpoint detection and response (EDR) monitoring, patches the Import Address Table, and disables kernel-level telemetry by abusing vulnerable signed drivers. Payloads are unpacked using over 90 mix-and-match encryption routines. For final execution, it uses a modified process ghosting technique, enhanced with kernel anti-peek measures to sanitize memory queries and disable image validation. Observed campaigns have targeted financial services (34%), healthcare (25%), and government (10%), with notable attacks impersonating the Indian Income Tax Department and the US Social Security Administration. Source: Infosecurity Magazine SC Staff Related Threat Intelligence Ostium trading platform loses $23.75 million in off-chain exploit SC Staff July 21, 2026 The attacker manipulated illegitimate price reports to disguise them as valid ones, then rapidly opened and closed large positions to generate artificial profits. Threat Intelligence HollowGraph malware uses Microsoft 365 calendar for command and control SC Staff July 20, 2026 HollowGraph, believed to be part of the Cavern command-and-control framework, targets organizations in Israel for espionage purposes. Threat Intelligence HelloNet campaign abuses ViPNet update mechanism to target Russian organizations SC Staff July 20, 2026 The HelloNet campaign targets organizations using ViPNet, a Russian information-security product suite commonly used in government and regulated environments. Related Events Cybercast Better Threat Intelligence Between Public and Private Sectors On-Demand Event Virtual Conference Nationwide Cybersecurity Summit 2025: Safeguarding America’s Digital Future On-Demand Event Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Account Harvesting DNS Spoofing Deauthentication Attack Defacement Denial of Service Dictionary Attack Domain Hijacking Hybrid Attack Information Warfare Reconnaissance You can skip this ad in 5 seconds

Share this article