Unpacking "Cruciferra": An Analysis of a Sophisticated Crypter Service
Essential information
- Published
- 20/07/2026 11:36
- Modified
- —
- Source / Author
- AlienVault
- Confidence
- 100/100
- Report type(s)
- threat-report
- Labels / Tags
- adaptixc2 agenttesla asyncrat byovd cruciferra crypter-service darkcloud stealer dcrat defense-evasion dll-sideloading edr-tampering formbook malware-as-a-service phantom stealer process-ghosting remcos snake keylogger valleyrat winos4.0 xloader xworm zgrat
- Related entities
- 72 indicators, 58 observables, 1 intrusion sets (apt), 20 techniques (mitre), 14 malware
Description
Cruciferra is a sophisticated crypter service utilized by multiple unrelated cybercriminal threat clusters to deliver remote access trojans and infostealers. Written in Mono, it employs extensive defense-evasion capabilities including indirect system calls, API unhooking, BYOVD-based EDR tampering, privilege escalation, and customized Process Ghosting for payload execution. The service features over 90 variations of cryptographic functions to obfuscate data and payloads, complicating static analysis and signature-based detection. Cruciferra was first advertised in fall 2025 with pricing tiers ranging from $450 to $2000 monthly. It has been observed in campaigns delivering various malware families including zgRAT, AgentTesla, AsyncRAT, XLoader, XWorm, Phantom Stealer, Formbook, and Remcos, primarily targeting financial services, healthcare, and government entities through opportunistic email-based attacks.