Cruciferra: The new crypter exploiting Windows vulnerabilities
We analyze how the Cruciferra group uses advanced BYOVD and Process Ghosting techniques to evade security and deploy malware on Windows systems.

The technical sophistication behind Cruciferra
The global cybersecurity landscape is facing a new threat. According to recent reports from Proofpoint, a China-linked cybercriminal group has begun using an advanced encryption service known as Cruciferra. This crypter does more than just hide malicious software; it allows various criminal groups to deploy payloads stealthily, bypassing traditional operating system defenses.
This discovery highlights a worrying trend: the democratization of complex attack tools that facilitate both espionage and large-scale ransomware distribution.
Evasion techniques: BYOVD and Process Ghosting
What sets Cruciferra apart from other conventional tools is its ability to integrate high-level attack techniques. To bypass security controls, the software employs two primary methods:
- BYOVD (Bring Your Own Vulnerable Driver): Attackers load legitimate but vulnerable drivers into the system to gain kernel-level privileges, overcoming Windows security protections.
- Process Ghosting: This technique allows for the execution of malicious code by replacing a file's content after it has been mapped into memory, making the process appear legitimate to antivirus software.
"The use of these tactics demonstrates that threat actors are increasingly investing in evasion of detection by abusing legitimate system functions," security experts note.
A growing risk for businesses and users
The group behind this tool has been detected using tax-related lures to deceive financial professionals and taxpayers, particularly in India. This type of hack shows that the entry vector remains social engineering, but the potential damage is multiplied by the effectiveness of the deployed malware.
It is essential to remember that network security does not depend solely on passive tools. If you are interested in understanding how attackers evolve, you can check out our analysis on SourTrade: The new hack that uses your browser to create malware, where we explore similar browser exploitation methods.
Mitigation recommendations
To protect against these types of threats, organizations should:
- Implement strict application control policies (AppLocker or WDAC).
- Actively monitor the loading of third-party drivers.
- Keep systems updated to close any known vulnerability that attackers might exploit using BYOVD techniques.
In conclusion, the emergence of Cruciferra is a reminder that attackers are refining their concealment methods. Constant vigilance and the adoption of a Zero Trust security model are the best defenses in an environment where malware is increasingly difficult to track.
Related articles
7 de septiembre de 2026
Cybersecurity: New ScreenConnect vulnerability facilitates attacks
Researchers have detected a four-stage infection chain that uses ScreenConnect to compromise systems through malicious scripts.
30 de agosto de 2026
Breach at Manchester Airports Group: The hack exposing 86 GB of data
The group FulcrumSec claims to have stolen 86 GB of data from Manchester Airports Group, revealing sensitive passenger and booking information.
23 de agosto de 2026
Hackers infect Android car systems: the new vulnerability
A supply chain attack is turning Android-based automotive multimedia systems into part of a botnet, putting driver security at risk.
16 de agosto de 2026
AmnesiaStealer: The new hack compromising macOS security
We analyze AmnesiaStealer, a macOS malware that enables remote browser control and puts user privacy at risk.
Loading comments...