Find notable cyber news and cases, enriched with sources, timelines, and signals.

Cruciferra crypter service's underground operating model

Threat Actor Meta
First reported
Last updated
Happening score
H score 29
1 unique sources, 1 articles

Summary

Hide ▲

Researchers observed Cruciferra operating as a paid crypter service used by multiple unrelated threat clusters, expanding the underground malware-delivery ecosystem and improving payload survival. The service was advertised for $450 to $2,000 a month and used to distribute RATs and information stealers. Its layered evasion features, including BYOVD-based EDR tampering and Process Ghosting, make malware harder to detect and analyze. The result is a more scalable concealment layer for opportunistic cybercrime.

Related Happenings

BusySnake Stealer Windows information-theft activity

Malware Activity
H score30 First: 03.07.2026 16:36 Last: 03.07.2026 16:36 Sources 1

About this happening: The BusySnake Stealer malware is being used against Windows systems to steal browser cookies, passwords, documents, screenshots, wallet files, and Telegram data, increasin...

Y2K Operators Millenium RAT social-engineering distribution campaign

Campaign
H score73 First: 29.06.2026 17:30 Last: 29.06.2026 17:30 Sources 1

About this happening: The Y2K Operators are running a social-engineering distribution campaign that spreads Millenium RAT through booby-trapped downloads, exposing users to remote compr...

Windows cryptocurrency clipper malware using USB LNK worming and Tor C2

Malware Activity
H score29 First: 18.06.2026 17:30 Last: 18.06.2026 17:30 Sources 1

About this happening: A Windows-based cryptocurrency clipper has been active since February 2026, using USB-delivered LNK worming to steal wallet data and reroute payments. The malware adds...

Windows cryptocurrency clipper campaign targeting users via USB LNK worms

Campaign
H score32 First: 18.06.2026 17:30 Last: 18.06.2026 17:30 Sources 1

About this happening: A Windows cryptocurrency clipper campaign is actively targeting users since February 2026, putting clipboard data, wallet addresses, and seed phrases at risk. The operatio...

TA4922 expanded European phishing-and-malware campaign

Campaign
H score40 First: 04.06.2026 00:45 Last: 04.06.2026 00:45 Sources 1

How related: "It's worth mentioning here that this attack was documented in detail earlier this month by Seqrite Labs and Cyderes Howler Cell. Seqrite Labs is tracking the activity under the moniker Operation DragonReturn."

About this happening: TA4922 is a China-linked cybercrime campaign that now also uses the Cruciferra crypter, while continuing its income tax-themed phishing activity against Indian t...

Timeline

  1. 27.07.2026 13:51 2 articles · 3h ago

    Cruciferra is sold as a subscription crypter for Windows malware delivery

    Campaign Scope Update

    Proofpoint found Cruciferra operating as a subscription crypter service used by multiple unrelated cybercriminal threat clusters to deliver RATs and information-stealer malware, including a China-linked group using income tax-themed phishing against Indian taxpayers, tax professionals, and corporate finance teams. The service was first made available for sale in fall 2025 and was advertised on the cybercrime underground as the "most lethal crypter" for $450 to $2,000 a month.

    Show sources