216.73.216.197

Unpacking "Cruciferra": An Analysis of a Sophisticated Crypter Service

· Published 20/07/2026 11:36

Export JSON

Essential information

Published
20/07/2026 11:36
Modified
Source / Author
AlienVault
Confidence
100/100
Report type(s)
threat-report
Labels / Tags
adaptixc2 agenttesla asyncrat byovd cruciferra crypter-service darkcloud stealer dcrat defense-evasion dll-sideloading edr-tampering formbook malware-as-a-service phantom stealer process-ghosting remcos snake keylogger valleyrat winos4.0 xloader xworm zgrat
Related entities
72 indicators, 58 observables, 1 intrusion sets (apt), 20 techniques (mitre), 14 malware

Description

Cruciferra is a sophisticated crypter service utilized by multiple unrelated cybercriminal threat clusters to deliver remote access trojans and infostealers. Written in Mono, it employs extensive capabilities including indirect system calls, API unhooking, -based EDR tampering, privilege escalation, and customized Process Ghosting for payload execution. The service features over 90 variations of cryptographic functions to obfuscate data and payloads, complicating static analysis and signature-based detection. Cruciferra was first advertised in fall 2025 with pricing tiers ranging from $450 to $2000 monthly. It has been observed in campaigns delivering various malware families including , , , , , , , and , primarily targeting financial services, healthcare, and government entities through opportunistic email-based attacks.

External references