As cited
Copy frozen at (site build).
Cruciferra Crypter Uses Process Ghosting to Evade Detection
No summary had been written when this copy was frozen.
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
Cruciferra Crypter Uses Process Ghosting to Evade Detection
Cruciferra crypter employs process ghosting and 90 custom ciphers to obfuscate malicious payloads deployed by multiple threat actors. The malware uses process ghosting, a technique that creates process handles without observable execution traces, to evade endpoint detection. The use of custom ciphers adds additional obfuscation layers to the encrypted payloads.
Why it matters: Security teams running endpoint detection and response (EDR) tools and monitoring process creation events need to watch for process ghosting techniques, as Cruciferra demonstrates how attackers can circumvent traditional detection methods to deliver payloads for various campaigns.
- Source published
- First seen by Cybersecurity Tracker