🟠 High  |  Source: The Hacker News


A sophisticated crypter service called Cruciferra is being used by multiple threat actors, including a China-linked group targeting Indian taxpayers via phishing lures, to conceal Windows malware. It employs advanced evasion techniques including Bring Your Own Vulnerable Driver (BYOVD) and Process Ghosting to bypass endpoint security controls. The fact it is available across unrelated criminal clusters suggests it may be offered as a service, significantly broadening its potential reach.

Security Architect’s Take: Review endpoint detection capabilities to ensure your EDR solution can detect BYOVD attacks by monitoring for vulnerable driver loads — consider deploying a Microsoft Vulnerable Driver Blocklist policy. Additionally, enforce strict email gateway controls and user awareness training around tax-themed phishing lures, particularly for finance teams handling sensitive corporate data.

Original advisory: Cruciferra Crypter Uses BYOVD and Process Ghosting to Hide Windows Malware