CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Cruciferra Crypter Uses BYOVD and Process Ghosting to Hide Windows Malware

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 3249

As cited

Copy frozen at (site build).

threat intel

Cruciferra Crypter Uses BYOVD and Process Ghosting to Hide Windows Malware

Researchers at Proofpoint identified Cruciferra, a crypter service linked to China-based cybercriminals, being deployed to deliver remote access malware while employing evasion techniques including bring your own vulnerable driver (BYOVD) and process ghosting to avoid detection on Windows systems. The service has been adopted by multiple unrelated cybercriminal groups targeting Indian taxpayers and finance professionals through tax-themed phishing campaigns.

Why it matters: Organizations and individuals in India receiving tax-related communications face elevated risk from malware distribution via a professionally maintained evasion toolkit; security teams should monitor for Cruciferra signatures and implement BYOVD and process-ghosting detection controls.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Cruciferra Crypter Uses BYOVD and Process Ghosting to Hide Windows Malware

Researchers at Proofpoint identified Cruciferra, a crypter service linked to China-based cybercriminals, being deployed to deliver remote access malware while employing evasion techniques including bring your own vulnerable driver (BYOVD) and process ghosting to avoid detection on Windows systems. The service has been adopted by multiple unrelated cybercriminal groups targeting Indian taxpayers and finance professionals through tax-themed phishing campaigns.

Why it matters: Organizations and individuals in India receiving tax-related communications face elevated risk from malware distribution via a professionally maintained evasion toolkit; security teams should monitor for Cruciferra signatures and implement BYOVD and process-ghosting detection controls.

VendorsMicrosoft
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary