Cruciferra crypter service's underground operating model
Threat Actor Meta
Summary
Hide ▲
Show ▼
Researchers observed Cruciferra operating as a paid crypter service used by multiple unrelated threat clusters, expanding the underground malware-delivery ecosystem and improving payload survival. The service was advertised for $450 to $2,000 a month and used to distribute RATs and information stealers. Its layered evasion features, including BYOVD-based EDR tampering and Process Ghosting, make malware harder to detect and analyze. The result is a more scalable concealment layer for opportunistic cybercrime.
Related Happenings
BusySnake Stealer Windows information-theft activity
Malware Activity
H score30
First: 03.07.2026 16:36
Last: 03.07.2026 16:36
Sources 1
About this happening:
The BusySnake Stealer malware is being used against Windows systems to steal browser cookies, passwords, documents, screenshots, wallet files, and Telegram data, increasin...
BusySnake Stealer Windows information-theft activity
Malware ActivityAbout this happening: The BusySnake Stealer malware is being used against Windows systems to steal browser cookies, passwords, documents, screenshots, wallet files, and Telegram data, increasin...
Y2K Operators Millenium RAT social-engineering distribution campaign
Campaign
H score73
First: 29.06.2026 17:30
Last: 29.06.2026 17:30
Sources 1
About this happening:
The Y2K Operators are running a social-engineering distribution campaign that spreads Millenium RAT through booby-trapped downloads, exposing users to remote compr...
Y2K Operators Millenium RAT social-engineering distribution campaign
CampaignAbout this happening: The Y2K Operators are running a social-engineering distribution campaign that spreads Millenium RAT through booby-trapped downloads, exposing users to remote compr...
Windows cryptocurrency clipper malware using USB LNK worming and Tor C2
Malware Activity
H score29
First: 18.06.2026 17:30
Last: 18.06.2026 17:30
Sources 1
About this happening:
A Windows-based cryptocurrency clipper has been active since February 2026, using USB-delivered LNK worming to steal wallet data and reroute payments. The malware adds...
Windows cryptocurrency clipper malware using USB LNK worming and Tor C2
Malware ActivityAbout this happening: A Windows-based cryptocurrency clipper has been active since February 2026, using USB-delivered LNK worming to steal wallet data and reroute payments. The malware adds...
Windows cryptocurrency clipper campaign targeting users via USB LNK worms
Campaign
H score32
First: 18.06.2026 17:30
Last: 18.06.2026 17:30
Sources 1
About this happening:
A Windows cryptocurrency clipper campaign is actively targeting users since February 2026, putting clipboard data, wallet addresses, and seed phrases at risk. The operatio...
Windows cryptocurrency clipper campaign targeting users via USB LNK worms
CampaignAbout this happening: A Windows cryptocurrency clipper campaign is actively targeting users since February 2026, putting clipboard data, wallet addresses, and seed phrases at risk. The operatio...
TA4922 expanded European phishing-and-malware campaign
Campaign
H score40
First: 04.06.2026 00:45
Last: 04.06.2026 00:45
Sources 1
How related:
"It's worth mentioning here that this attack was documented in detail earlier this month by Seqrite Labs and Cyderes Howler Cell. Seqrite Labs is tracking the activity under the moniker Operation DragonReturn."
About this happening:
TA4922 is a China-linked cybercrime campaign that now also uses the Cruciferra crypter, while continuing its income tax-themed phishing activity against Indian t...
TA4922 expanded European phishing-and-malware campaign
CampaignHow related: "It's worth mentioning here that this attack was documented in detail earlier this month by Seqrite Labs and Cyderes Howler Cell. Seqrite Labs is tracking the activity under the moniker Operation DragonReturn."
About this happening: TA4922 is a China-linked cybercrime campaign that now also uses the Cruciferra crypter, while continuing its income tax-themed phishing activity against Indian t...
Timeline
-
27.07.2026 13:51 2 articles · 3h ago
Cruciferra is sold as a subscription crypter for Windows malware delivery
Campaign Scope UpdateProofpoint found Cruciferra operating as a subscription crypter service used by multiple unrelated cybercriminal threat clusters to deliver RATs and information-stealer malware, including a China-linked group using income tax-themed phishing against Indian taxpayers, tax professionals, and corporate finance teams. The service was first made available for sale in fall 2025 and was advertised on the cybercrime underground as the "most lethal crypter" for $450 to $2,000 a month.
Show sources
- Cruciferra Crypter Uses BYOVD and Process Ghosting to Hide Windows Malware — thehackernews.com — 27.07.2026 13:51
- Cruciferra Crypter Uses BYOVD and Process Ghosting to Hide Windows Malware — thehackernews.com — 27.07.2026 13:51