Unpacking "Cruciferra": An Analysis of a Sophisticated Crypter Service
Cruciferra is a sophisticated crypter service utilized by multiple unrelated cybercriminal threat clusters to deliver remote access trojans and infostealers. Written in Mono, it employs extensive defense-evasion capabilities including indirect system calls, API unhooking, BYOVD-based EDR tampering, privilege escalation, and customized Process Ghosting for payload execution. The service features over 90 variations of cryptographic functions to obfuscate data and payloads, complicating static analysis and signature-based detection. Cruciferra was first advertised in fall 2025 with pricing tiers ranging from $450 to $2000 monthly. It has been observed in campaigns delivering various malware families including zgRAT, AgentTesla, AsyncRAT, XLoader, XWorm, Phantom Stealer, Formbook, and Remcos, primarily targeting financial services, healthcare, and government entities through opportunistic email-based attacks.
AI Analysis
Technical Summary
Cruciferra is a commercial crypter service written in Mono that supports multiple unrelated cybercriminal threat clusters by enabling delivery of remote access trojans and infostealers. It incorporates extensive defense-evasion capabilities including indirect system calls, API unhooking, BYOVD-based EDR tampering, privilege escalation, and customized Process Ghosting for payload execution. The service features over 90 variations of cryptographic functions to obfuscate payloads, hindering static analysis and signature-based detection. Advertised since fall 2025 with pricing tiers from $450 to $2000 monthly, Cruciferra has been used in campaigns delivering malware such as zgRAT, AgentTesla, AsyncRAT, XLoader, XWorm, Phantom Stealer, Formbook, and Remcos. These campaigns primarily target financial services, healthcare, and government entities through opportunistic email-based attacks. The threat actor TA4922 is associated with this service. There are no known exploits or patches since this is a malware service rather than a software vulnerability.
Potential Impact
Cruciferra enables multiple cybercriminal groups to evade detection and deliver a variety of remote access trojans and infostealers, potentially leading to unauthorized access, data theft, and compromise of targeted organizations in financial services, healthcare, and government sectors. Its advanced obfuscation and defense-evasion techniques complicate detection and analysis by security tools and analysts. However, as a malware-as-a-service offering, it is not a software vulnerability and does not have a direct patch or fix.
Mitigation Recommendations
Since Cruciferra is a commercial crypter service used by threat actors rather than a software vulnerability, no patch or official fix exists. Organizations should focus on standard security controls such as email filtering, user awareness training to prevent phishing, and endpoint detection and response solutions capable of detecting behavior-based indicators of compromise related to the malware families delivered by Cruciferra. Monitoring for indicators associated with TA4922 and related malware campaigns is recommended. There is no vendor advisory or patch applicable.
Indicators of Compromise
- hash: 09bedbf7a41e0f8dabe4f41d331db58373ce15b2e9204540873a1884f38bdde1
- domain: almacensantangel.com
- domain: gatuso.duckdns.org
- hash: 5b4f59236a9b950bcd5191b35d19125f60cfb9e1a1e1aa2e4f914b6745dde9df
- hash: 68fec379f2ae76c3d2ce913f7be650cea1d06990
- hash: 5761bd63da03686fc480245da7bd1e9f
- hash: 4f1773a1228e2c009cbcf61e9e550e01
- hash: 2aa47fb23074e8ae776a369f9e28d1a2f6e70739
- hash: 17aae57cf6255c7eb169bf62ea67376d9708976eb7831f8cdd0ea38bdcb37dc4
- hash: bc61ef6d7ad9ee878028f24d50e9dcf6d7d88bf2
- hash: 26b2da88cb95b98b46bb985f67f76154
- hash: 2fdfdd13a0c548bb68c9d5aa8599a9265d4659da3e237fe7a42ac6ac06b9a06a
- hash: 3c181f642e24c28602a87be7f195e2f3d1ffa30b37e20f5121d99f88b22ab80e
- url: https://almacensantangel.com/wp-includes/assets/YourSSA_Documents_0000000676152_05_187_2026_Document_0000000676152.rar
- domain: 0zbqnac1t4dv2t2wuodv1m.com
- domain: digital-magicians.com
- domain: fiusyevr.live
- ip: 89.34.90.99
- domain: fvxcuvuyte.live
- hash: 63bfd6567f4c704e8ed6530f5cdd704e
- hash: 080fdb73a6bbc99625c2190730257d1e54723952
- hash: 3f31aee0948d16f8d64bf6bec69a4331099993e502b11bfc56b2c0112024489d
- hash: 59ad96dd3b4d5f10a5c53bbd465446e52dc7701a4ac633632f762bf1336d3347
- hash: 66dbe675480dc229e5b3ab8ad74207f73486e64e57805074f784bb2e01bcb865
- hash: 6dbd6f9f2fa636c16ac4fa81418b68a604424861b9650dd9c4f2b0ba6f67d6ac
- hash: 7887e919555fb5948c217556ba149392a72982b1bc427d3db779db9dcbf09ee8
- hash: a6fb779be35592fb0ff624a8f8e12ab3cafe7bcfc312cd98263814db7fb01e02
- hash: c46e907886e2158cbc453e767183aecf07887b5ac8848f19684451883d69f5f0
- hash: c4e93449453cf67c5d5605bb8f425207a738a242fdb432d720acc32faa74926c
- hash: c5b1e9aafc8f2b4ab05effc00fd43f3114b9ef1d592a086c952793ac4e299809
- url: http://faeytrdeaw.gu.cc
- url: http://figyuyrqwr.gu.cc
- url: http://fiusyevr.live
- url: http://fuaytrwese.love
- url: http://hfyuayustrv.gu.cc
- url: http://hsahyteiows.gu.cc
- url: http://jaiydteds.love
- url: http://jsiruytrawey.gu.cc
- url: http://kawosyetw.gu.cc
- url: http://kawuuterta.gu.cc
- url: http://laiwutrencr.gu.cc
- url: http://lasiduutfe.gu.cc
- url: http://lisiutegrm.live
- url: http://maisytawe.gu.cc
- url: http://mksfuuerwo.live
- url: http://ncduuyese.live
- url: http://nciyeyrawoe.gu.cc
- url: http://nviuawusye.gu.cc
- url: http://nvsieyrrawe.gu.cc
- url: http://paiwudyea.love
- url: http://pmcjsuyraw.gu.cc
- url: http://qeuasytua.love
- url: http://svuatwea.love
- url: http://syfiaydytea.live
- url: http://viuyeyrwqs.gu.cc
- url: http://vusuydryt.love
- url: http://xkcifgieusr.gu.cc
- url: http://xnbscuya.love
- url: http://xuastyrdqk.love
- url: http://yicoweytcbtw.gu.cc
- url: https://digital-magicians.com/photo295825092412.zip?_r=ea623202
- url: https://fvxcuvuyte.live
- url: https://hsauyeet.live
- url: https://kdsuyrse.live
- url: https://oakwusya.love
- domain: fuaytrwese.love
- domain: hsauyeet.live
- domain: jaiydteds.love
- domain: kdsuyrse.live
- domain: lisiutegrm.live
- domain: mksfuuerwo.live
- domain: ncduuyese.live
- domain: oakwusya.love
- domain: paiwudyea.love
- domain: qeuasytua.love
- domain: svuatwea.love
- domain: syfiaydytea.live
- domain: vusuydryt.love
- domain: xnbscuya.love
- domain: xuastyrdqk.love
Unpacking "Cruciferra": An Analysis of a Sophisticated Crypter Service
Description
Cruciferra is a sophisticated crypter service utilized by multiple unrelated cybercriminal threat clusters to deliver remote access trojans and infostealers. Written in Mono, it employs extensive defense-evasion capabilities including indirect system calls, API unhooking, BYOVD-based EDR tampering, privilege escalation, and customized Process Ghosting for payload execution. The service features over 90 variations of cryptographic functions to obfuscate data and payloads, complicating static analysis and signature-based detection. Cruciferra was first advertised in fall 2025 with pricing tiers ranging from $450 to $2000 monthly. It has been observed in campaigns delivering various malware families including zgRAT, AgentTesla, AsyncRAT, XLoader, XWorm, Phantom Stealer, Formbook, and Remcos, primarily targeting financial services, healthcare, and government entities through opportunistic email-based attacks.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Cruciferra is a commercial crypter service written in Mono that supports multiple unrelated cybercriminal threat clusters by enabling delivery of remote access trojans and infostealers. It incorporates extensive defense-evasion capabilities including indirect system calls, API unhooking, BYOVD-based EDR tampering, privilege escalation, and customized Process Ghosting for payload execution. The service features over 90 variations of cryptographic functions to obfuscate payloads, hindering static analysis and signature-based detection. Advertised since fall 2025 with pricing tiers from $450 to $2000 monthly, Cruciferra has been used in campaigns delivering malware such as zgRAT, AgentTesla, AsyncRAT, XLoader, XWorm, Phantom Stealer, Formbook, and Remcos. These campaigns primarily target financial services, healthcare, and government entities through opportunistic email-based attacks. The threat actor TA4922 is associated with this service. There are no known exploits or patches since this is a malware service rather than a software vulnerability.
Potential Impact
Cruciferra enables multiple cybercriminal groups to evade detection and deliver a variety of remote access trojans and infostealers, potentially leading to unauthorized access, data theft, and compromise of targeted organizations in financial services, healthcare, and government sectors. Its advanced obfuscation and defense-evasion techniques complicate detection and analysis by security tools and analysts. However, as a malware-as-a-service offering, it is not a software vulnerability and does not have a direct patch or fix.
Defensive Guidance
Since Cruciferra is a commercial crypter service used by threat actors rather than a software vulnerability, no patch or official fix exists. Organizations should focus on standard security controls such as email filtering, user awareness training to prevent phishing, and endpoint detection and response solutions capable of detecting behavior-based indicators of compromise related to the malware families delivered by Cruciferra. Monitoring for indicators associated with TA4922 and related malware campaigns is recommended. There is no vendor advisory or patch applicable.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://www.proofpoint.com/us/blog/threat-insight/unpacking-cruciferra-analysis-sophisticated-crypter-service"]
- Adversary
- TA4922
- Pulse Id
- 6a5dec09c0c4b7d2a00d7b2c
- Threat Score
- null
Indicators of Compromise
Hash
| Value | Description | Copy |
|---|---|---|
hash09bedbf7a41e0f8dabe4f41d331db58373ce15b2e9204540873a1884f38bdde1 | — | |
hash5b4f59236a9b950bcd5191b35d19125f60cfb9e1a1e1aa2e4f914b6745dde9df | — | |
hash68fec379f2ae76c3d2ce913f7be650cea1d06990 | — | |
hash5761bd63da03686fc480245da7bd1e9f | — | |
hash4f1773a1228e2c009cbcf61e9e550e01 | — | |
hash2aa47fb23074e8ae776a369f9e28d1a2f6e70739 | — | |
hash17aae57cf6255c7eb169bf62ea67376d9708976eb7831f8cdd0ea38bdcb37dc4 | — | |
hashbc61ef6d7ad9ee878028f24d50e9dcf6d7d88bf2 | — | |
hash26b2da88cb95b98b46bb985f67f76154 | — | |
hash2fdfdd13a0c548bb68c9d5aa8599a9265d4659da3e237fe7a42ac6ac06b9a06a | — | |
hash3c181f642e24c28602a87be7f195e2f3d1ffa30b37e20f5121d99f88b22ab80e | — | |
hash63bfd6567f4c704e8ed6530f5cdd704e | — | |
hash080fdb73a6bbc99625c2190730257d1e54723952 | — | |
hash3f31aee0948d16f8d64bf6bec69a4331099993e502b11bfc56b2c0112024489d | — | |
hash59ad96dd3b4d5f10a5c53bbd465446e52dc7701a4ac633632f762bf1336d3347 | — | |
hash66dbe675480dc229e5b3ab8ad74207f73486e64e57805074f784bb2e01bcb865 | — | |
hash6dbd6f9f2fa636c16ac4fa81418b68a604424861b9650dd9c4f2b0ba6f67d6ac | — | |
hash7887e919555fb5948c217556ba149392a72982b1bc427d3db779db9dcbf09ee8 | — | |
hasha6fb779be35592fb0ff624a8f8e12ab3cafe7bcfc312cd98263814db7fb01e02 | — | |
hashc46e907886e2158cbc453e767183aecf07887b5ac8848f19684451883d69f5f0 | — | |
hashc4e93449453cf67c5d5605bb8f425207a738a242fdb432d720acc32faa74926c | — | |
hashc5b1e9aafc8f2b4ab05effc00fd43f3114b9ef1d592a086c952793ac4e299809 | — |
Domain
| Value | Description | Copy |
|---|---|---|
domainalmacensantangel.com | — | |
domaingatuso.duckdns.org | — | |
domain0zbqnac1t4dv2t2wuodv1m.com | — | |
domaindigital-magicians.com | — | |
domainfiusyevr.live | — | |
domainfvxcuvuyte.live | — | |
domainfuaytrwese.love | — | |
domainhsauyeet.live | — | |
domainjaiydteds.love | — | |
domainkdsuyrse.live | — | |
domainlisiutegrm.live | — | |
domainmksfuuerwo.live | — | |
domainncduuyese.live | — | |
domainoakwusya.love | — | |
domainpaiwudyea.love | — | |
domainqeuasytua.love | — | |
domainsvuatwea.love | — | |
domainsyfiaydytea.live | — | |
domainvusuydryt.love | — | |
domainxnbscuya.love | — | |
domainxuastyrdqk.love | — |
Url
| Value | Description | Copy |
|---|---|---|
urlhttps://almacensantangel.com/wp-includes/assets/YourSSA_Documents_0000000676152_05_187_2026_Document_0000000676152.rar | — | |
urlhttp://faeytrdeaw.gu.cc | — | |
urlhttp://figyuyrqwr.gu.cc | — | |
urlhttp://fiusyevr.live | — | |
urlhttp://fuaytrwese.love | — | |
urlhttp://hfyuayustrv.gu.cc | — | |
urlhttp://hsahyteiows.gu.cc | — | |
urlhttp://jaiydteds.love | — | |
urlhttp://jsiruytrawey.gu.cc | — | |
urlhttp://kawosyetw.gu.cc | — | |
urlhttp://kawuuterta.gu.cc | — | |
urlhttp://laiwutrencr.gu.cc | — | |
urlhttp://lasiduutfe.gu.cc | — | |
urlhttp://lisiutegrm.live | — | |
urlhttp://maisytawe.gu.cc | — | |
urlhttp://mksfuuerwo.live | — | |
urlhttp://ncduuyese.live | — | |
urlhttp://nciyeyrawoe.gu.cc | — | |
urlhttp://nviuawusye.gu.cc | — | |
urlhttp://nvsieyrrawe.gu.cc | — | |
urlhttp://paiwudyea.love | — | |
urlhttp://pmcjsuyraw.gu.cc | — | |
urlhttp://qeuasytua.love | — | |
urlhttp://svuatwea.love | — | |
urlhttp://syfiaydytea.live | — | |
urlhttp://viuyeyrwqs.gu.cc | — | |
urlhttp://vusuydryt.love | — | |
urlhttp://xkcifgieusr.gu.cc | — | |
urlhttp://xnbscuya.love | — | |
urlhttp://xuastyrdqk.love | — | |
urlhttp://yicoweytcbtw.gu.cc | — | |
urlhttps://digital-magicians.com/photo295825092412.zip?_r=ea623202 | — | |
urlhttps://fvxcuvuyte.live | — | |
urlhttps://hsauyeet.live | — | |
urlhttps://kdsuyrse.live | — | |
urlhttps://oakwusya.love | — |
Ip
| Value | Description | Copy |
|---|---|---|
ip89.34.90.99 | — |
Threat ID: 6a5e02712a4a8d5989efa0af
Added to database: 07/20/2026, 11:11:45 UTC
Last enriched: 08/19/2026, 10:57:17 UTC
Last updated: 09/03/2026, 07:00:36 UTC
Views: 136
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.