SyncWave Blog
Cybersecurity 2 min read 97

Cruciferra: The new crypter exploiting Windows vulnerabilities

We analyze how the Cruciferra group uses advanced BYOVD and Process Ghosting techniques to evade security and deploy malware on Windows systems.

cybersecurity digital lock

The technical sophistication behind Cruciferra

The global cybersecurity landscape is facing a new threat. According to recent reports from Proofpoint, a China-linked cybercriminal group has begun using an advanced encryption service known as Cruciferra. This crypter does more than just hide malicious software; it allows various criminal groups to deploy payloads stealthily, bypassing traditional operating system defenses.

This discovery highlights a worrying trend: the democratization of complex attack tools that facilitate both espionage and large-scale ransomware distribution.

Evasion techniques: BYOVD and Process Ghosting

What sets Cruciferra apart from other conventional tools is its ability to integrate high-level attack techniques. To bypass security controls, the software employs two primary methods:

  1. BYOVD (Bring Your Own Vulnerable Driver): Attackers load legitimate but vulnerable drivers into the system to gain kernel-level privileges, overcoming Windows security protections.
  2. Process Ghosting: This technique allows for the execution of malicious code by replacing a file's content after it has been mapped into memory, making the process appear legitimate to antivirus software.

"The use of these tactics demonstrates that threat actors are increasingly investing in evasion of detection by abusing legitimate system functions," security experts note.

A growing risk for businesses and users

The group behind this tool has been detected using tax-related lures to deceive financial professionals and taxpayers, particularly in India. This type of hack shows that the entry vector remains social engineering, but the potential damage is multiplied by the effectiveness of the deployed malware.

It is essential to remember that network security does not depend solely on passive tools. If you are interested in understanding how attackers evolve, you can check out our analysis on SourTrade: The new hack that uses your browser to create malware, where we explore similar browser exploitation methods.

Mitigation recommendations

To protect against these types of threats, organizations should:

  • Implement strict application control policies (AppLocker or WDAC).
  • Actively monitor the loading of third-party drivers.
  • Keep systems updated to close any known vulnerability that attackers might exploit using BYOVD techniques.

In conclusion, the emergence of Cruciferra is a reminder that attackers are refining their concealment methods. Constant vigilance and the adoption of a Zero Trust security model are the best defenses in an environment where malware is increasingly difficult to track.

Share:

Comments

Loading comments...

Contact

Want to get in touch?

Questions, suggestions or proposals — write to us and we will respond.