ShellCodeX Intelligence Brief
HIGH
Cybersecurity
Cruciferra crypter blends BYOVD with process ghosting for Windows malware
Source headline: Cruciferra Crypter Uses BYOVD and Process Ghosting to Hide Windows Malware
Threat level
High
Signal strength
75/100
Source confidence
1 source
Published
3 hours ago
Intelligence Summary
A China-linked cybercrime operation is using the Cruciferra crypter service to distribute Windows malware. Proofpoint reports that Cruciferra has been reused by multiple threat clusters for different payloads. The technique combines BYOVD to leverage vulnerable signed drivers with process ghosting to reduce detection. Targeting has focused on tax-related phishing lures aimed at Indian taxpayers, tax professionals, and corporate finance teams. Organizations receiving tax-themed emails should verify attachments and monitor for suspicious driver and process behavior.
Recommended Action
Review affected assets, schedule urgent remediation, and monitor related indicators.
Topics
Original reporting
The Hacker News
Cruciferra Crypter Uses BYOVD and Process Ghosting to Hide Windows Malware
Open original source