As cited
Copy frozen at (site build).
threat intel
Cruciferra Crypter Uses BYOVD and Process Ghosting to Hide Windows Malware
Researchers at Proofpoint identified Cruciferra, a crypter service linked to China-based cybercriminals, being deployed to deliver remote access malware while employing evasion techniques including bring your own vulnerable driver (BYOVD) and process ghosting to avoid detection on Windows systems. The service has been adopted by multiple unrelated cybercriminal groups targeting Indian taxpayers and finance professionals through tax-themed phishing campaigns.
Why it matters: Organizations and individuals in India receiving tax-related communications face elevated risk from malware distribution via a professionally maintained evasion toolkit; security teams should monitor for Cruciferra signatures and implement BYOVD and process-ghosting detection controls.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
Cruciferra Crypter Uses BYOVD and Process Ghosting to Hide Windows Malware
Researchers at Proofpoint identified Cruciferra, a crypter service linked to China-based cybercriminals, being deployed to deliver remote access malware while employing evasion techniques including bring your own vulnerable driver (BYOVD) and process ghosting to avoid detection on Windows systems. The service has been adopted by multiple unrelated cybercriminal groups targeting Indian taxpayers and finance professionals through tax-themed phishing campaigns.
Why it matters: Organizations and individuals in India receiving tax-related communications face elevated risk from malware distribution via a professionally maintained evasion toolkit; security teams should monitor for Cruciferra signatures and implement BYOVD and process-ghosting detection controls.
- Source published
- First seen by Cybersecurity Tracker