Unpacking “Cruciferra”: An Analysis of a Sophisticated Crypter Service
Cruciferra is a sophisticated Mono-based crypter-as-a-service offering used by multiple cybercrime threat clusters to obfuscate and deliver commodity malware including AsyncRAT, XWorm, zgRAT, AgentTesla, and others. It employs DLL side-loading for initial execution, then applies extensive defense-evasion techniques including indirect syscalls, API/IAT unhooking, BYOVD-based EDR tampering via vulnerable kernel drivers, UAC bypass, and a modified Process Ghosting variant that patches EDR inspection functions. The crypter uses over 90 polymorphically generated custom encryption algorithms derived from components of established ciphers, significantly complicating static analysis and signature-based detection.
- domain0zbqnac1t4dv2t2wuodv1m[.]comzgRAT C2 server used in Cruciferra-delivered zgRAT campaign (observed June 2026)
- domaingatuso[.]duckdns[.]orgXWorm C2 server used in Cruciferra-delivered XWorm campaign (observed May 2026)
- emaile[.]shohei[.]y[@]jcom[.]zaq[.]ne[.]jpSender email address used in TA4922 phishing campaign impersonating Indian Income Tax Department to deliver Cruciferra
- ip89[.]34[.]90[.]99zgRAT C2 server IP (port 56001) used in Cruciferra-delivered zgRAT campaign (observed June 2026)
- sha25609bedbf7a41e0f8dabe4f41d331db58373ce15b2e9204540873a1884f38bdde1BYOVD vulnerable kernel driver NTIOLib_X64.sys, dropped by Cruciferra to terminate EDR processes
- sha25617aae57cf6255c7eb169bf62ea67376d9708976eb7831f8cdd0ea38bdcb37dc4BYOVD vulnerable kernel driver Core64.sys, dropped by Cruciferra to terminate EDR processes
- sha2562fdfdd13a0c548bb68c9d5aa8599a9265d4659da3e237fe7a42ac6ac06b9a06aSHA256 hash of GoFlyDrv.sys, the primary BYOVD vulnerable kernel driver dropped by Cruciferra to terminate EDR processes via IOCTL
- sha2563c181f642e24c28602a87be7f195e2f3d1ffa30b37e20f5121d99f88b22ab80eSHA256 hash of TA4922 Cruciferra/AsyncRAT payload ZIP archive (Tax-Number52563.zip, observed April 2026)
- sha2563f31aee0948d16f8d64bf6bec69a4331099993e502b11bfc56b2c0112024489dSHA256 hash of Cruciferra/zgRAT payload ZIP archive (photo295825092412.zip, observed June 2026)
- sha25659ad96dd3b4d5f10a5c53bbd465446e52dc7701a4ac633632f762bf1336d3347TA4922 Cruciferra/AsyncRAT payload (Tax-Number101863.zip, 28 May 2026)
- sha2565b4f59236a9b950bcd5191b35d19125f60cfb9e1a1e1aa2e4f914b6745dde9dfBYOVD vulnerable kernel driver ProcessMonitorDriver.sys, dropped by Cruciferra to terminate EDR processes
- sha25666dbe675480dc229e5b3ab8ad74207f73486e64e57805074f784bb2e01bcb865TA4922 Cruciferra/AsyncRAT payload (Tax-Number809863.zip, 4 May 2026)
- sha2566dbd6f9f2fa636c16ac4fa81418b68a604424861b9650dd9c4f2b0ba6f67d6acTA4922 Cruciferra/AsyncRAT payload (Tax-Number33863.zip, 1 June 2026)
- sha2567887e919555fb5948c217556ba149392a72982b1bc427d3db779db9dcbf09ee8BYOVD vulnerable kernel driver MemoryInformer.sys, dropped by Cruciferra to terminate EDR processes
- sha256a6fb779be35592fb0ff624a8f8e12ab3cafe7bcfc312cd98263814db7fb01e02TA4922 Cruciferra/AsyncRAT payload (Tax-Number119863.zip, 28 May 2026)
- sha256c46e907886e2158cbc453e767183aecf07887b5ac8848f19684451883d69f5f0BYOVD vulnerable kernel driver selfprot.sys, dropped by Cruciferra to terminate EDR processes
- sha256c4e93449453cf67c5d5605bb8f425207a738a242fdb432d720acc32faa74926cBYOVD vulnerable kernel driver HwOs2Ec.sys, dropped by Cruciferra to terminate EDR processes
- sha256c5b1e9aafc8f2b4ab05effc00fd43f3114b9ef1d592a086c952793ac4e299809BYOVD vulnerable kernel driver LnvMSRIO.sys, dropped by Cruciferra to terminate EDR processes
- urlhxxp://faeytrdeaw[.]gu[.]ccTA4922 Cruciferra/AsyncRAT payload URL (4 May 2026)
- urlhxxp://figyuyrqwr[.]gu[.]ccTA4922 Cruciferra/AsyncRAT payload URL (4 May 2026)
- urlhxxp://fiusyevr[.]liveTA4922 Cruciferra/AsyncRAT payload URL (1 June 2026)
- urlhxxp://fuaytrwese[.]loveTA4922 Cruciferra/AsyncRAT payload URL (28 May 2026)
- urlhxxp://hfyuayustrv[.]gu[.]ccTA4922 Cruciferra/AsyncRAT payload URL (4 May 2026)
- urlhxxp://hsahyteiows[.]gu[.]ccTA4922 Cruciferra/AsyncRAT payload URL (28 April 2026)
- urlhxxp://jaiydteds[.]loveTA4922 Cruciferra/AsyncRAT payload URL (1 June 2026)
- urlhxxp://jsiruytrawey[.]gu[.]ccTA4922 Cruciferra/AsyncRAT payload URL (4 May 2026)
- urlhxxp://kawosyetw[.]gu[.]ccTA4922 Cruciferra/AsyncRAT payload URL (4 May 2026)
- urlhxxp://kawuuterta[.]gu[.]ccTA4922 Cruciferra/AsyncRAT payload URL (4 May 2026)
- urlhxxp://laiwutrencr[.]gu[.]ccTA4922 Cruciferra/AsyncRAT payload URL (4 May 2026)
- urlhxxp://lasiduutfe[.]gu[.]ccTA4922 Cruciferra/AsyncRAT payload staging URL (observed April 2026)
- urlhxxp://lisiutegrm[.]liveTA4922 Cruciferra/AsyncRAT payload URL (1 June 2026)
- urlhxxp://maisytawe[.]gu[.]ccTA4922 Cruciferra/AsyncRAT payload URL (4 May 2026)
- urlhxxp://mksfuuerwo[.]liveTA4922 Cruciferra/AsyncRAT payload URL (1 June 2026)
- urlhxxp://ncduuyese[.]liveTA4922 Cruciferra/AsyncRAT payload URL (28 May 2026)
- urlhxxp://nciyeyrawoe[.]gu[.]ccTA4922 Cruciferra/AsyncRAT payload URL (28 April 2026)
- urlhxxp://nviuawusye[.]gu[.]ccTA4922 Cruciferra/AsyncRAT payload URL (4 May 2026)
- urlhxxp://nvsieyrrawe[.]gu[.]ccTA4922 Cruciferra/AsyncRAT payload URL (4 May 2026)
- urlhxxp://paiwudyea[.]loveTA4922 Cruciferra/AsyncRAT payload URL (1 June 2026)
- urlhxxp://pmcjsuyraw[.]gu[.]ccTA4922 Cruciferra/AsyncRAT payload URL (4 May 2026)
- urlhxxp://qeuasytua[.]loveTA4922 Cruciferra/AsyncRAT payload URL (28 May 2026)
- urlhxxps://almacensantangel[.]com/wp-includes/assets/YourSSA_Documents_0000000676152_05_187_2026_Document_0000000676152[.]rarCruciferra/XWorm payload download URL disguised as SSA tax document (observed May 2026)
- urlhxxps://digital-magicians[.]com/photo295825092412[.]zip?_r=ea623202Cruciferra/zgRAT payload download URL (observed June 2026)
- urlhxxps://fvxcuvuyte[.]liveTA4922 Cruciferra/AsyncRAT payload URL (1 June 2026)
- urlhxxps://hsauyeet[.]liveTA4922 Cruciferra/AsyncRAT payload URL (1 June 2026)
- urlhxxps://kdsuyrse[.]liveTA4922 Cruciferra/AsyncRAT payload URL (1 June 2026)
- urlhxxps://oakwusya[.]loveTA4922 Cruciferra/AsyncRAT payload URL (28 May 2026)
- urlhxxp://svuatwea[.]loveTA4922 Cruciferra/AsyncRAT payload URL (28 May 2026)
- urlhxxp://syfiaydytea[.]liveTA4922 Cruciferra/AsyncRAT payload URL (28 May 2026)
- urlhxxp://viuyeyrwqs[.]gu[.]ccTA4922 Cruciferra/AsyncRAT payload URL (4 May 2026)
- urlhxxp://vusuydryt[.]loveTA4922 Cruciferra/AsyncRAT payload URL (28 May 2026)
- urlhxxp://xkcifgieusr[.]gu[.]ccTA4922 Cruciferra/AsyncRAT payload URL (4 May 2026)
- urlhxxp://xnbscuya[.]loveTA4922 Cruciferra/AsyncRAT payload URL (28 May 2026)
- urlhxxp://xuastyrdqk[.]loveTA4922 Cruciferra/AsyncRAT payload URL (1 June 2026)
- urlhxxp://yicoweytcbtw[.]gu[.]ccTA4922 Cruciferra/AsyncRAT payload URL (28 April 2026)
Detection / Hunteropenrouter
What Happened
Security researchers have identified a service called Cruciferra, which is a tool criminals buy to make their malware harder to detect by antivirus software. Criminals rent this tool for $450 to $2,000 per month and use it to package well-known malicious programs (like remote access trojans and data-stealing malware) so they can slip past security defenses. The tool is delivered through phishing emails that pretend to be from government tax agencies or the Social Security Administration, tricking people into downloading infected files. Once running, Cruciferra actively disables security software, hides its presence, and uses over 90 different custom encryption methods to avoid being identified. Organizations in finance, healthcare, and government are the most frequent targets. Defenders should be aware of the specific indicators provided, update their detection tools, and educate employees about these phishing tactics.
Key Takeaways
- Cruciferra is a sophisticated Mono-based crypter service advertised on cybercrime forums, priced $450-$2000/month, used by multiple unrelated threat actors to deliver commodity RATs and infostealers
- Employs extensive defense evasion including indirect syscalls, API/IAT unhooking, BYOVD-based EDR tampering using vulnerable drivers (e.g., GoFlyDrv.sys), UAC bypass, and a modified Process Ghosting technique that patches ZwQueryVirtualMemory and NtManageHotPatch to evade EDR memory inspection
- Uses over 90 polymorphically generated custom encryption algorithms assembled from components of established ciphers (Keccak, SPECK-128/256, Threefish, DES-CBC, Feistel, ARX variants), making static analysis and signature-based detection extremely difficult
- TA4922, a Chinese-speaking cybercrime actor, conducted multiple campaigns using tax-themed lures impersonating Indian government tax authorities to deliver Cruciferra-packed AsyncRAT
- PE metadata fields (Copyright, Product, Description) follow a predictable random-word format that can be used for tracking samples across VirusTotal
Affected Systems
- Microsoft Windows endpoints (all modern versions supporting DLL side-loading and COM elevation)
- Organizations in financial services, healthcare, and government sectors (most frequently targeted verticals)
Vulnerabilities (CVEs)
None identified.
Attack Chain
- Initial Access: Phishing emails with tax/government/SSA-themed lures contain URLs or PDF attachments with embedded links to attacker-controlled landing pages
- Execution: Victim downloads ZIP archive containing a legitimate executable and a malicious DLL; running the executable triggers DLL side-loading of Cruciferra code
- Defense Evasion: Cruciferra unhooking ntdll/kernel32/advapi32 APIs via clean KnownDlls mapping, repairs IAT, uses indirect syscalls, hides console windows, disables Windows notifications via registry modifications
- Privilege Escalation: If not running as admin, Cruciferra bypasses UAC via COM Elevation Moniker; drops vulnerable kernel driver (e.g., GoFlyDrv.sys) for BYOVD-based EDR process termination
- Persistence: Writes to Software\Microsoft\Windows\CurrentVersion\Run registry key with value 'putty' for reboot persistence
- Payload Execution: Decrypts payload from .reloc section using custom Base16 encoding and one of 90+ custom encryption algorithms; executes via modified Process Ghosting with ZwQueryVirtualMemory and NtManageHotPatch hooking to evade EDR memory inspection
Detection Availability
- YARA Rules: Yes
- Sigma Rules: No
- Snort/Suricata Rules: No
- KQL Queries: No
- Splunk SPL Queries: No
- EQL Queries: No
- Other Detection Logic: No
- Platforms: Proofpoint, VirusTotal
The article references YARA signatures and PE metadata formatting used to track Cruciferra-packed samples in VirusTotal. No rule bodies are provided in the article itself, but the authors describe using YARA signatures combined with metadata pattern matching for ongoing tracking.
Detection Engineering Assessment
| Dimension | Rating | Rationale |
|---|---|---|
| EDR Visibility | Low | Cruciferra is specifically designed to evade EDR through API unhooking, IAT unhooking, indirect syscalls, BYOVD-based EDR process termination, and modified Process Ghosting that patches ZwQueryVirtualMemory and NtManageHotPatch. These techniques actively neuter EDR telemetry, making post-evasion visibility very limited. Pre-evasion DLL side-loading and initial driver drop may be visible if EDR catches the early stages. |
| Network Visibility | Medium | Payload staging URLs and C2 communications (e.g., zgRAT C2 on 89.34.90.99:56001, XWorm C2 on gatuso.duckdns.org) are observable at the network level. However, initial system fingerprinting and payload downloads may use standard HTTPS, limiting deep inspection without TLS decryption. |
| Detection Difficulty | Hard | Cruciferra's multi-layered evasion (unhooking, indirect syscalls, BYOVD, Process Ghosting with EDR patching) actively defeats most endpoint telemetry. Over 90 polymorphic encryption algorithms and randomized PE metadata frustrate static signatures. DLL side-loading with hundreds of decoy exports complicates dynamic analysis. Detection requires behavioral correlation across multiple telemetry sources and may need kernel-level visibility. |
Required Log Sources
- Sysmon Event ID 1 (Process Creation) - for DLL side-loading patterns
- Sysmon Event ID 7 (Image Loaded) - for DLL loading anomalies
- Sysmon Event ID 11 (File Creation) - for driver drops and ZIP extraction
- Sysmon Event ID 13 (Registry Value Set) - for Run key and notification disabling modifications
- Sysmon Event ID 6 (Driver Loaded) - for BYOVD driver loading
- Windows Event Log 4688 (Process Creation)
- EDR telemetry for memory manipulation and API unhooking behaviors
- Network firewall/proxy logs for staging URL and C2 connections
Hunting Hypotheses
| Hypothesis | Telemetry | ATT&CK Stage | FP Risk |
|---|---|---|---|
| Consider hunting for processes loading DLLs from the same directory as the executing binary, especially when the DLL has hundreds of exported functions with randomized names, as this pattern is consistent with Cruciferra's DLL side-loading technique | Sysmon Event ID 7 (Image Loaded) correlated with Sysmon Event ID 1 (Process Creation) to identify DLLs loaded from non-standard paths alongside their parent executable | Execution | Medium - legitimate applications may use DLL side-loading; focus on executables with random-word PE metadata and unusually high export counts |
| Consider hunting for kernel driver loading events involving known vulnerable driver filenames (GoFlyDrv.sys, Core64.sys, HwOs2Ec.sys, LnvMSRIO.sys, MemoryInformer.sys, NTIOLib_X64.sys, ProcessMonitorDriver.sys, selfprot.sys) outside of expected hardware vendor installation contexts | Sysmon Event ID 6 (Driver Loaded) and EDR kernel driver telemetry | Defense Evasion | Low - these drivers are associated with specific hardware utilities and should not appear in typical enterprise environments outside of their original software packages |
| Consider hunting for processes that map clean copies of ntdll.dll from KnownDlls and subsequently modify memory regions in other loaded modules, as this behavior is consistent with Cruciferra's API unhooking technique | EDR memory access telemetry, Sysmon Event ID 10 (ProcessAccess) for cross-process memory operations | Defense Evasion | Medium - some legitimate security tools and debuggers may access KnownDlls; correlate with subsequent process termination or hook removal patterns |
| Consider hunting for registry modifications to notification-related keys (ToastEnabled, Balloon, ShowInfoTip) combined with a Run key entry named 'putty', as this combination is characteristic of Cruciferra's stealth and persistence behavior | Sysmon Event ID 13 (Registry Value Set) and Windows Event Log 4657 | Persistence / Defense Evasion | Low - the specific combination of notification disabling and a Run key named 'putty' is highly suspicious and unlikely in legitimate use |
| Consider hunting for PE files with Copyright metadata matching the pattern of a year followed by 2-4 random words (e.g., '2026 Colpoplastric Semipreactical Group') and random-word Product/Description fields, as this metadata format is consistent across Cruciferra samples | EDR file metadata scanning, VirusTotal API queries, or SIEM-correlated file analysis events | Initial Access / Execution | Low - the specific random-word pattern in PE metadata is distinctive and not typical of legitimate software |
Control Gaps
- Signature-based AV/EDR detection is significantly impaired by 90+ polymorphic custom encryption algorithms and randomized PE metadata
- EDR inline hooks on ntdll.dll are bypassed via indirect syscalls using clean stub pointers read from disk
- BYOVD technique terminates EDR processes at kernel level, potentially blinding endpoint telemetry entirely
- Modified Process Ghosting with ZwQueryVirtualMemory and NtManageHotPatch patching prevents EDR from validating in-memory image sections against disk
- Console window hiding via EnumWindows/SW_HIDE loop may evade user-reported suspicious activity
- Notification suppression via registry modifications may prevent Windows Defender/SmartScreen alerts from reaching the user
Key Behavioral Indicators
- Executable and DLL pair extracted from ZIP archive with DLL loaded via side-loading (T1574.001)
- PE files with hundreds of exported functions with randomized names pointing to junk code
- Process mapping clean ntdll.dll from \KnownDlls\ and overwriting hooked memory regions
- Background thread looping 100 times with 50ms sleep calling EnumWindows to find and hide ConsoleWindowClass windows
- Kernel driver loading of GoFlyDrv.sys, Core64.sys, or other listed vulnerable drivers outside hardware vendor context
- Registry Run key with value name 'putty' pointing to attacker executable
- PE metadata Copyright field matching pattern: year + 2-4 random words (e.g., '2026 Colpoplastric Semipreactical Group')
- NtManageHotPatch function patched with 6-byte payload in remote process ntdll.dll
- Base16 decoding using custom character set 'PQRSTUVWXYZ[]^_' for payload stored in .reloc section
False Positive Assessment
Low - The combination of DLL side-loading with hundreds of decoy exports, BYOVD driver drops, notification suppression via registry, Run key persistence with 'putty' value name, and randomized PE metadata creates a highly distinctive behavioral fingerprint. Individual indicators (e.g., a single vulnerable driver load) may produce false positives, but the full chain is unlikely to appear in legitimate activity.
Recommendations
Immediate Mitigation
- Verify against your organization's incident response runbook and team escalation paths before acting. Consider blocking the identified C2 domains and IPs (gatuso.duckdns.org, 0zbqnac1t4dv2t2wuodv1m.com, 89.34.90.99) at network perimeter controls if supported by your tooling.
- Consider adding the identified payload staging URLs and domains (*.gu.cc, *.love, *.live patterns from TA4922 campaigns) to web proxy and DNS filtering blocklists where applicable.
- If your EDR supports it, consider deploying block rules for the listed BYOVD vulnerable kernel driver hashes to prevent driver-based EDR tampering.
- Consider searching endpoint telemetry for the listed SHA256 hashes of Cruciferra delivery archives and payloads to identify potentially compromised hosts.
Infrastructure Hardening
- Evaluate whether enabling Windows Defender Application Control (WDAC) or similar application whitelisting could prevent execution of unsigned/untrusted DLLs alongside legitimate executables, mitigating DLL side-loading.
- Consider deploying Microsoft's vulnerable driver blocklist if not already enabled, as it may block several of the BYOVD drivers used by Cruciferra.
- If your environment supports it, consider enabling kernel-mode code integrity (HVCI) to prevent unsigned or vulnerable kernel drivers from loading.
- Evaluate whether TLS inspection on web proxy infrastructure could improve visibility into payload staging downloads from the identified URLs.
User Protection
- Consider deploying email gateway rules to flag or block messages containing URLs to domains matching the observed TA4922 staging patterns (*.gu.cc, *.love, *.live with random subdomains).
- If supported by your email platform, consider enabling external sender warning banners and URL rewriting for messages impersonating government tax authorities or the Social Security Administration.
- Consider blocking execution of executables and DLLs extracted from ZIP archives in user-writable directories via application control policies where feasible.
Security Awareness
- Consider incorporating tax-themed and government impersonation phishing scenarios into existing security awareness training, particularly ahead of tax filing deadlines.
- Consider reminding employees that legitimate government agencies do not distribute tax documents or penalty notices via unsolicited email attachments or download links.
- If applicable to your awareness program, consider educating users to report emails containing guest complaint or bed bug notification themes, as these lures have been observed in Cruciferra campaigns targeting hospitality and travel sectors.
MITRE ATT&CK Mapping
Execution
Persistence
Privilege Escalation
Stealth
Defense Impairment
Additional IOCs
- Urls:
hxxp://hsahyteiows[.]gu[.]cc- TA4922 Cruciferra/AsyncRAT payload URL (28 April 2026)hxxp://yicoweytcbtw[.]gu[.]cc- TA4922 Cruciferra/AsyncRAT payload URL (28 April 2026)hxxp://nciyeyrawoe[.]gu[.]cc- TA4922 Cruciferra/AsyncRAT payload URL (28 April 2026)hxxp://xkcifgieusr[.]gu[.]cc- TA4922 Cruciferra/AsyncRAT payload URL (4 May 2026)hxxp://viuyeyrwqs[.]gu[.]cc- TA4922 Cruciferra/AsyncRAT payload URL (4 May 2026)hxxp://pmcjsuyraw[.]gu[.]cc- TA4922 Cruciferra/AsyncRAT payload URL (4 May 2026)hxxp://laiwutrencr[.]gu[.]cc- TA4922 Cruciferra/AsyncRAT payload URL (4 May 2026)hxxp://maisytawe[.]gu[.]cc- TA4922 Cruciferra/AsyncRAT payload URL (4 May 2026)hxxp://kawosyetw[.]gu[.]cc- TA4922 Cruciferra/AsyncRAT payload URL (4 May 2026)hxxp://nviuawusye[.]gu[.]cc- TA4922 Cruciferra/AsyncRAT payload URL (4 May 2026)hxxp://faeytrdeaw[.]gu[.]cc- TA4922 Cruciferra/AsyncRAT payload URL (4 May 2026)hxxp://figyuyrqwr[.]gu[.]cc- TA4922 Cruciferra/AsyncRAT payload URL (4 May 2026)hxxp://hfyuayustrv[.]gu[.]cc- TA4922 Cruciferra/AsyncRAT payload URL (4 May 2026)hxxp://jsiruytrawey[.]gu[.]cc- TA4922 Cruciferra/AsyncRAT payload URL (4 May 2026)hxxp://kawuuterta[.]gu[.]cc- TA4922 Cruciferra/AsyncRAT payload URL (4 May 2026)hxxp://nvsieyrrawe[.]gu[.]cc- TA4922 Cruciferra/AsyncRAT payload URL (4 May 2026)hxxp://fuaytrwese[.]love- TA4922 Cruciferra/AsyncRAT payload URL (28 May 2026)hxxp://qeuasytua[.]love- TA4922 Cruciferra/AsyncRAT payload URL (28 May 2026)hxxp://svuatwea[.]love- TA4922 Cruciferra/AsyncRAT payload URL (28 May 2026)hxxp://vusuydryt[.]love- TA4922 Cruciferra/AsyncRAT payload URL (28 May 2026)hxxp://xnbscuya[.]love- TA4922 Cruciferra/AsyncRAT payload URL (28 May 2026)hxxp://ncduuyese[.]live- TA4922 Cruciferra/AsyncRAT payload URL (28 May 2026)hxxps://oakwusya[.]love- TA4922 Cruciferra/AsyncRAT payload URL (28 May 2026)hxxp://syfiaydytea[.]live- TA4922 Cruciferra/AsyncRAT payload URL (28 May 2026)hxxp://jaiydteds[.]love- TA4922 Cruciferra/AsyncRAT payload URL (1 June 2026)hxxp://mksfuuerwo[.]live- TA4922 Cruciferra/AsyncRAT payload URL (1 June 2026)hxxp://fiusyevr[.]live- TA4922 Cruciferra/AsyncRAT payload URL (1 June 2026)hxxp://lisiutegrm[.]live- TA4922 Cruciferra/AsyncRAT payload URL (1 June 2026)hxxp://paiwudyea[.]love- TA4922 Cruciferra/AsyncRAT payload URL (1 June 2026)hxxp://xuastyrdqk[.]love- TA4922 Cruciferra/AsyncRAT payload URL (1 June 2026)hxxps://fvxcuvuyte[.]live- TA4922 Cruciferra/AsyncRAT payload URL (1 June 2026)hxxps://kdsuyrse[.]live- TA4922 Cruciferra/AsyncRAT payload URL (1 June 2026)hxxps://hsauyeet[.]live- TA4922 Cruciferra/AsyncRAT payload URL (1 June 2026)
- File Hashes:
66dbe675480dc229e5b3ab8ad74207f73486e64e57805074f784bb2e01bcb865(SHA256) - TA4922 Cruciferra/AsyncRAT payload (Tax-Number809863.zip, 4 May 2026)a6fb779be35592fb0ff624a8f8e12ab3cafe7bcfc312cd98263814db7fb01e02(SHA256) - TA4922 Cruciferra/AsyncRAT payload (Tax-Number119863.zip, 28 May 2026)59ad96dd3b4d5f10a5c53bbd465446e52dc7701a4ac633632f762bf1336d3347(SHA256) - TA4922 Cruciferra/AsyncRAT payload (Tax-Number101863.zip, 28 May 2026)6dbd6f9f2fa636c16ac4fa81418b68a604424861b9650dd9c4f2b0ba6f67d6ac(SHA256) - TA4922 Cruciferra/AsyncRAT payload (Tax-Number33863.zip, 1 June 2026)17aae57cf6255c7eb169bf62ea67376d9708976eb7831f8cdd0ea38bdcb37dc4(SHA256) - BYOVD vulnerable kernel driver Core64.sys, dropped by Cruciferra to terminate EDR processesc4e93449453cf67c5d5605bb8f425207a738a242fdb432d720acc32faa74926c(SHA256) - BYOVD vulnerable kernel driver HwOs2Ec.sys, dropped by Cruciferra to terminate EDR processesc5b1e9aafc8f2b4ab05effc00fd43f3114b9ef1d592a086c952793ac4e299809(SHA256) - BYOVD vulnerable kernel driver LnvMSRIO.sys, dropped by Cruciferra to terminate EDR processes7887e919555fb5948c217556ba149392a72982b1bc427d3db779db9dcbf09ee8(SHA256) - BYOVD vulnerable kernel driver MemoryInformer.sys, dropped by Cruciferra to terminate EDR processes09bedbf7a41e0f8dabe4f41d331db58373ce15b2e9204540873a1884f38bdde1(SHA256) - BYOVD vulnerable kernel driver NTIOLib_X64.sys, dropped by Cruciferra to terminate EDR processes5b4f59236a9b950bcd5191b35d19125f60cfb9e1a1e1aa2e4f914b6745dde9df(SHA256) - BYOVD vulnerable kernel driver ProcessMonitorDriver.sys, dropped by Cruciferra to terminate EDR processesc46e907886e2158cbc453e767183aecf07887b5ac8848f19684451883d69f5f0(SHA256) - BYOVD vulnerable kernel driver selfprot.sys, dropped by Cruciferra to terminate EDR processes
- Registry Keys:
Software\Microsoft\Windows\CurrentVersion\PushNotifications- Cruciferra sets ToastEnabled=0 to suppress Windows toast notifications including Defender/SmartScreen alertsSoftware\Microsoft\Windows\CurrentVersion\Explorer\Advanced- Cruciferra modifies Balloon and ShowInfoTip values to suppress classic notification balloons and infotipsSoftware\Microsoft\Windows\CurrentVersion\Run- Cruciferra establishes persistence by writing a Run key with default value 'putty' to execute after reboot
- File Paths:
Tax-Number52563.zip- TA4922 Cruciferra delivery archive containing executable and DLL pair for DLL side-loadingTax-Number809863.zip- TA4922 Cruciferra delivery archive (4 May 2026)Tax-Number119863.zip- TA4922 Cruciferra delivery archive (28 May 2026)Tax-Number101863.zip- TA4922 Cruciferra delivery archive (28 May 2026)Tax-Number33863.zip- TA4922 Cruciferra delivery archive (1 June 2026)photo295825092412.zip- Cruciferra/zgRAT delivery archive (29 June 2026)GoFlyDrv.sys- Primary BYOVD vulnerable kernel driver dropped by Cruciferra for EDR process terminationCore64.sys- Alternative BYOVD vulnerable kernel driver used by CruciferraHwOs2Ec.sys- Alternative BYOVD vulnerable kernel driver used by CruciferraLnvMSRIO.sys- Alternative BYOVD vulnerable kernel driver used by CruciferraMemoryInformer.sys- Alternative BYOVD vulnerable kernel driver used by CruciferraNTIOLib_X64.sys- Alternative BYOVD vulnerable kernel driver used by CruciferraProcessMonitorDriver.sys- Alternative BYOVD vulnerable kernel driver used by Cruciferraselfprot.sys- Alternative BYOVD vulnerable kernel driver used by Cruciferra
- Command Lines:
- Purpose: Guest complaint campaign used a zipped LNK file to launch a PowerShell command that fingerprinted the system, reported to a C2 server, and downloaded a ZIP archive containing Cruciferra | Tools:
powershell.exe,lnk| Stage: Initial Access / Execution
- Purpose: Guest complaint campaign used a zipped LNK file to launch a PowerShell command that fingerprinted the system, reported to a C2 server, and downloaded a ZIP archive containing Cruciferra | Tools: