Proofpoint analyzed Cruciferra, a crypter service sold on Exploit.in and used by multiple unrelated threat actors to deliver payloads such as AsyncRAT, XWorm, zgRAT, and other stealers and RATs. The service relies on heavy defense evasion, including DLL side-loading, BYOVD tampering, indirect syscalls, IAT unhooking, and a customized Process Ghosting variant, while new builds and test samples show it is still actively evolving. #Cruciferra #Proofpoint #TA4922 #AsyncRAT #XWorm #zgRAT
Keypoints
- Cruciferra is a crypter service used by multiple unrelated cybercriminal groups, not a single threat actor.
- Proofpoint observed it delivering many payloads, including AsyncRAT, XWorm, zgRAT, AgentTesla, Remcos, Formbook, and others.
- The service is advertised on Exploit.in and appears to be sold in tiers, with prices ranging from $450 to $2,000 per month.
- Cruciferra uses extensive defense evasion, including DLL side-loading, indirect syscalls, IAT unhooking, BYOVD-based EDR tampering, and customized Process Ghosting.
- It supports more than 90 custom encryption variants, making static analysis and signature-based detection difficult.
- Proofpoint identified both production and testing variants, indicating active development and ongoing refinement.
- Observed campaigns targeted multiple sectors, especially financial services, healthcare, government, and hospitality/travel, often through tax- or complaint-themed lures.
MITRE Techniques
- [T1027 ] Obfuscated Files or Information – Cruciferra heavily encrypts and custom-obfuscates payloads and strings to hinder analysis (‘uses over 90 variations of cryptographic functions to obfuscate its data and payloads’).
- [T1218 ] Signed Binary Proxy Execution – DLL Side-Loading – The infection chain relies on a legitimate executable loading a malicious DLL (‘when the target runs the executable file, the DLL … is side-loaded’).
- [T1055 ] Process Injection – Process Ghosting variant is used to map and run payloads in memory while minimizing disk artifacts (‘a variant of Process Ghosting’).
- [T1106 ] Native API – Cruciferra uses direct Windows native API activity and syscall-based execution paths to reduce visibility (‘uses indirect syscalls’).
- [T1562.001 ] Impair Defenses: Disable or Modify Tools – It tampers with EDR via BYOVD and hook removal (‘attempts to disable endpoint defenses like EDR’ and ‘repairs the IAT to remove any IAT hooks’).
- [T1036 ] Masquerading – The service uses trusted-looking lures and filenames, such as tax and SSA themes and benign-looking internal names (‘default value of “putty”’ and tax-themed lures).
- [T1112 ] Modify Registry – Cruciferra creates persistence and suppresses notifications by changing registry keys (‘writes to the registry SoftwareMicrosoftWindowsCurrentVersionRun key’).
- [T1053.005 ] Scheduled Task/Job: Scheduled Task – Not explicitly described as a task, not included.
- [T1047 ] Windows Management Instrumentation – Not mentioned in the article, not included.
- [T1105 ] Ingress Tool Transfer – It can download payloads from a staging server (‘download a payload from a staging server’).
- [T1021 ] Remote Services – Not mentioned in the article, not included.
- [T1041 ] Exfiltration Over C2 Channel – The guest-complaint campaign fingerprints the host and sends results to an actor-controlled server (‘reported the collected information to an actor-controlled server’).
- [T1204 ] User Execution – The campaigns rely on victims opening email attachments or URLs to launch the infection chain (‘if clicked, ran an executable’).
Indicators of Compromise
- [Domains/URLs ] TA4922 payload delivery URLs – hxxp://hsahyteiows[.]gu[.]cc, hxxp://yicoweytcbtw[.]gu[.]cc, and other similar gu[.]cc / love / live domains.
- [Domains ] C2 and hosting infrastructure – gatuso[.]duckdns[.]org, 0zbqnac1t4dv2t2wuodv1m[.]com, and 89[.]34[.]90[.]99:56001.
- [File hashes ] ZIP and payload SHA256 values – 3c181f642e24c28602a87be7f195e2f3d1ffa30b37e20f5121d99f88b22ab80e, 66dbe675480dc229e5b3ab8ad74207f73486e64e57805074f784bb2e01bcb865, and other hashes.
- [File names ] Delivery archives and payload containers – Tax-Number52563.zip, Tax-Number809863.zip, photo295825092412.zip, and YourSSA_Documents_0000000676152_05_187_2026_Document_0000000676152.rar.
- [Driver files ] BYOVD helper drivers used for defense evasion – GoFlyDrv.sys, Core64.sys, and HwOs2Ec.sys.
- [Registry keys ] Persistence and notification-suppression locations – SoftwareMicrosoftWindowsCurrentVersionRun, SoftwareMicrosoftWindowsCurrentVersionPushNotificationsToastEnabled, and SoftwareMicrosoftWindowsCurrentVersionExplorerAdvancedBalloon.