CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Cruciferra Crypter Uses Process Ghosting to Evade Detection

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 6360

As cited

Copy frozen at (site build).

Cruciferra Crypter Uses Process Ghosting to Evade Detection

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Cruciferra Crypter Uses Process Ghosting to Evade Detection

Cruciferra crypter employs process ghosting and 90 custom ciphers to obfuscate malicious payloads deployed by multiple threat actors. The malware uses process ghosting, a technique that creates process handles without observable execution traces, to evade endpoint detection. The use of custom ciphers adds additional obfuscation layers to the encrypted payloads.

Why it matters: Security teams running endpoint detection and response (EDR) tools and monitoring process creation events need to watch for process ghosting techniques, as Cruciferra demonstrates how attackers can circumvent traditional detection methods to deliver payloads for various campaigns.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary