Return to Threats

Cruciferra Crypter Uses BYOVD and Process Ghosting to Hide Windows Malware

thehackernews.com 2026-07-27 malicious AI use High

What Happened

The China-linked cybercrime group behind the use of income tax-related phishing lures targeting Indian taxpayers, tax professionals, and corporate finance teams has been observed using a sophisticated crypter service called Cruciferra. According to a new analysis by Proofpoint, Cruciferra has been utilized by various unrelated cybercriminal threat clusters to deliver a wide array of remote

Why It Matters

Report facts: Proofpoint documents "Cruciferra" as a sophisticated crypter‑as‑a‑service, written in Mono and sold on underground forums since late 2025, used by multiple unrelated cybercrime clusters (including China‑linked actors) to conceal remote access trojans and infostealers delivered via Windows malware campaigns.[1][7][8][11] The service bundles advanced evasion techniques such as BYOVD‑based EDR tampering, indirect system calls, API/IAT unhooking, DLL side‑loading, privilege escalation, and a customized Process Ghosting implementation, plus more than 90 mix‑and‑match encryption routines to defeat static and behavioral detection.[4][7][8][9][10][11] RealGround analysis: While Cruciferra itself targets traditional Windows environments, its crypter‑as‑a‑service model and defense‑evasion stack are directly relevant to AI security because similar tooling can be used to hide malware inside data collection pipelines, agent host processes, or model-serving infrastructure, increasing the risk of malicious AI use and AI supply chain compromise. Organizations deploying AI agents and model-services should adopt continuous red teaming and CISO‑level governance to simulate such evasion

Healthcare Fintech SaaS SMB AI startups

RealGround Analysis

This signal maps to malicious AI use. Organizations using AI agents, LLM APIs, SaaS integrations, or sensitive data workflows should review whether this class of issue could create unauthorized tool execution, data leakage, weak approval gates, or unmanaged supply-chain exposure.

Recommended Actions

  • Restrict AI agent tool permissions and production write paths.
  • Review sensitive data access across prompts, logs, embeddings, memory, and SaaS integrations.
  • Add human approval workflows for high-impact or state-changing actions.
  • Run prompt injection and indirect prompt injection tests against affected workflows.
  • Document the owner, control gap, and remediation deadline for this risk class.

Source

https://thehackernews.com/2026/07/cruciferra-crypter-uses-byovd-and.html

Talk to AI CISO