ShellCodeX
Tools • Events • News • Insights
ShellCodeX Intelligence Brief
HIGH Cybersecurity

Cruciferra crypter blends BYOVD with process ghosting for Windows malware

Source headline: Cruciferra Crypter Uses BYOVD and Process Ghosting to Hide Windows Malware

Threat level High
Signal strength 75/100
Source confidence 1 source
Published 3 hours ago

Intelligence Summary

A China-linked cybercrime operation is using the Cruciferra crypter service to distribute Windows malware. Proofpoint reports that Cruciferra has been reused by multiple threat clusters for different payloads. The technique combines BYOVD to leverage vulnerable signed drivers with process ghosting to reduce detection. Targeting has focused on tax-related phishing lures aimed at Indian taxpayers, tax professionals, and corporate finance teams. Organizations receiving tax-themed emails should verify attachments and monitor for suspicious driver and process behavior.

Recommended Action

Review affected assets, schedule urgent remediation, and monitor related indicators.

Topics

#phishing #windows #evasion #byovd #crypter #process-ghosting
Original reporting The Hacker News Cruciferra Crypter Uses BYOVD and Process Ghosting to Hide Windows Malware
Open original source