Cruciferra is a sophisticated Mono-based crypter-as-a-service offering used by multiple cybercrime threat clusters to obfuscate and deliver commodity malware including AsyncRAT, XWorm, zgRAT, AgentTesla, and others. It employs DLL side-loading for initial execution, then applies extensive defense-evasion techniques including indirect syscalls, API/IAT unhooking, BYOVD-based EDR tampering via vulnerable kernel drivers, UAC bypass, and a modified Process Ghosting variant that patches EDR inspection functions. The crypter uses over 90 polymorphically generated custom encryption algorithms derived from components of established ciphers, significantly complicating static analysis and signature-based detection.
Crypter
1 post
Unpacking “Cruciferra”: An Analysis of a Sophisticated Crypter Service