Cruciferra: The new crypter exploiting Windows vulnerabilities
We analyze how the Cruciferra group uses advanced BYOVD and Process Ghosting techniques to evade security and deploy malware on Windows systems.

The technical sophistication behind Cruciferra
The global cybersecurity landscape is facing a new threat. According to recent reports from Proofpoint, a China-linked cybercriminal group has begun using an advanced encryption service known as Cruciferra. This crypter does more than just hide malicious software; it allows various criminal groups to deploy payloads stealthily, bypassing traditional operating system defenses.
This discovery highlights a worrying trend: the democratization of complex attack tools that facilitate both espionage and large-scale ransomware distribution.
Evasion techniques: BYOVD and Process Ghosting
What sets Cruciferra apart from other conventional tools is its ability to integrate high-level attack techniques. To bypass security controls, the software employs two primary methods:
- BYOVD (Bring Your Own Vulnerable Driver): Attackers load legitimate but vulnerable drivers into the system to gain kernel-level privileges, overcoming Windows security protections.
- Process Ghosting: This technique allows for the execution of malicious code by replacing a file's content after it has been mapped into memory, making the process appear legitimate to antivirus software.
"The use of these tactics demonstrates that threat actors are increasingly investing in evasion of detection by abusing legitimate system functions," security experts note.
A growing risk for businesses and users
The group behind this tool has been detected using tax-related lures to deceive financial professionals and taxpayers, particularly in India. This type of hack shows that the entry vector remains social engineering, but the potential damage is multiplied by the effectiveness of the deployed malware.
It is essential to remember that network security does not depend solely on passive tools. If you are interested in understanding how attackers evolve, you can check out our analysis on SourTrade: The new hack that uses your browser to create malware, where we explore similar browser exploitation methods.
Mitigation recommendations
To protect against these types of threats, organizations should:
- Implement strict application control policies (AppLocker or WDAC).
- Actively monitor the loading of third-party drivers.
- Keep systems updated to close any known vulnerability that attackers might exploit using BYOVD techniques.
In conclusion, the emergence of Cruciferra is a reminder that attackers are refining their concealment methods. Constant vigilance and the adoption of a Zero Trust security model are the best defenses in an environment where malware is increasingly difficult to track.
Related articles
27 de julio de 2026
Cruciferra: El nou crypter que explota vulnerabilitats de Windows
Analitzem com el grup Cruciferra utilitza tècniques avançades de BYOVD i Process Ghosting per evadir la seguretat i desplegar malware en sistemes Windows.
27 de julio de 2026
Cruciferra: El nuevo crypter que explota vulnerabilidades de Windows
Analizamos cómo el grupo Cruciferra utiliza técnicas avanzadas de BYOVD y Process Ghosting para evadir la seguridad y desplegar malware en sistemas Windows.
26 de julio de 2026
SourTrade: El nou hack que utilitza el teu navegador per crear malware
La campanya SourTrade redefineix el malvertising en obligar el navegador de l'usuari a assemblar malware peça a peça, evitant així els mètodes de detecció.
26 de julio de 2026
SourTrade: The new hack that uses your browser to build malware
The SourTrade campaign redefines malvertising by forcing the user's browser to assemble malware piece by piece, bypassing traditional detection methods.
Loading comments...