New Crypter-as-a-Service Cruciferra Fuels Stealthy Malware Attacks Worldwide
Proofpoint uncovered Cruciferra, a crypter-as-a-service that helps hackers evade antivirus and deliver malware in multiple campaigns. Proofpoint’s research team traced a wave of income-tax-themed lures targeting Indian taxpayers, tax professionals, and corporate finance teams back to a crypter service called Cruciferra, and the tool turns out to be shared infrastructure used across multiple unrelated criminal […]

Proofpoint’s research team traced a wave of income-tax-themed lures targeting Indian taxpayers, tax professionals, and corporate finance teams back to a crypter service called Cruciferra, and the tool turns out to be shared infrastructure used across multiple unrelated criminal groups.
A crypter’s job is simple to describe and hard to build well: scramble a malicious payload so antivirus tools can’t detect it, then unwrap it at just the right moment on the victim’s machine. Cruciferra does that job with a level of polish researchers don’t see often. It’s written in Mono and packs in indirect system calls, API unhooking, and a custom flavor of Process Ghosting designed to leave almost nothing behind for a forensic investigator to find.
Related breach coverage
- Thailand’s Ministry of Finance Targeted With Hermes AI Agent Running Unattended, Hades Implant Staged2026-07-24
Hunt.io uncovered a cyber-espionage attack on Thailand’s Finance Ministry using Hermes AI agent and Hades malware for reconnaissance and persistence. Researchers at Hunt.io have uncovered an intrusion targeting Thailand’s Ministry of Finance that offers a rare look inside a live cyber-espionage operation. Instead of recovering malware after the fact, the team found exposed staging servers […]
- Dysphoria Botnet Uses Blockchain Domains to Hide C2 Infrastructure2026-07-28
Researchers uncovered the 200,000-device Dysphoria botnet, which uses Ethereum and Solana domains to hide its command servers. QiAnXin XLab, jointly with China’s CNCERT, disclosed Dysphoria, a botnet that has compromised roughly 200,000 devices worldwide and uses Ethereum and Solana blockchain domain names to hide its command infrastructure. The botnet evolved from jackskid and fbot malware […]
- Daxin: 13-Year-Old China-Linked Malware Found Still Active on Manufacturer’s Network2026-07-18
Researchers found China’s Daxin rootkit and a new Stupig backdoor on a Taiwan firm’s network, suggesting a stealthy intrusion dating back to 2013. Symantec’s Threat Hunter Team found Daxin running on a compromised host at a Taiwan-based subsidiary of a multinational high-tech manufacturer in 2026. Daxin is a Windows kernel-mode rootkit that Symantec first documented […]
- US, Allies Warn of Russian Cyberattacks Targeting Critical Infrastructure Routers2026-07-14
Multiple state-sponsored APTs are compromising poorly secured devices across critical infrastructure sector networks. The post US, Allies Warn of Russian Cyberattacks Targeting Critical Infrastructure Routers appeared first on SecurityWeek.
