Unpacking "Cruciferra": An Analysis of a Sophisticated Crypter Service
Cruciferra is a sophisticated crypter service utilized by multiple unrelated cybercriminal threat clusters to deliver remote access trojans and infostealers. Written in Mono, it employs extensive defense-evasion capabilities including indirect system calls, API unhooking, BYOVD-based EDR tampering, privilege escalation, and customized Process Ghosting for payload execution. The service features over 90 variations of cryptographic functions to obfuscate data and payloads, complicating static analysis and signature-based detection. Cruciferra was first advertised in fall 2025 with pricing tiers ranging from $450 to $2000 monthly. It has been observed in campaigns delivering various malware families including zgRAT, AgentTesla, AsyncRAT, XLoader, XWorm, Phantom Stealer, Formbook, and Remcos, primarily targeting financial services, healthcare, and government entities through opportunistic email-based attacks.
AI Analysis
Technical Summary
Cruciferra is a malware-as-a-service crypter platform written in Mono that facilitates delivery of multiple remote access trojans and infostealers by diverse cybercriminal clusters. It incorporates extensive defense-evasion capabilities including indirect system calls, API unhooking, BYOVD-based EDR tampering, privilege escalation, and customized process ghosting for payload execution. The service uses over 90 cryptographic function variants to obfuscate data and payloads, hindering static analysis and signature-based detection. Advertised since fall 2025 with pricing from $450 to $2000 monthly, Cruciferra has been linked to campaigns distributing malware such as zgRAT, AgentTesla, AsyncRAT, XLoader, XWorm, Phantom Stealer, Formbook, and Remcos. These campaigns primarily target financial services, healthcare, and government entities through opportunistic email phishing attacks. There is no indication of a software vulnerability or patch; this is a threat actor tool facilitating malware delivery.
Potential Impact
Cruciferra enables cybercriminals to evade detection and deliver a variety of remote access trojans and information stealers effectively. Its advanced obfuscation and defense-evasion techniques complicate detection by security products, increasing the risk of successful compromise of targeted organizations in financial, healthcare, and government sectors. The service's availability as malware-as-a-service lowers the barrier for multiple unrelated threat actors to conduct sophisticated attacks. However, there are no known exploits in the wild targeting software vulnerabilities, as Cruciferra itself is a malicious tool rather than a vulnerability.
Mitigation Recommendations
As Cruciferra is a malware service rather than a software vulnerability, no patches or official fixes exist. Defenders should focus on detecting and blocking phishing emails and payloads associated with the malware families distributed via Cruciferra. Employing advanced endpoint detection and response solutions capable of identifying behavior consistent with process ghosting, API unhooking, and EDR tampering may help mitigate infection risk. Monitoring threat intelligence sources for indicators related to Cruciferra campaigns is recommended. There is no vendor patch or remediation applicable to this threat.
Indicators of Compromise
- hash: 09bedbf7a41e0f8dabe4f41d331db58373ce15b2e9204540873a1884f38bdde1
- domain: almacensantangel.com
- domain: gatuso.duckdns.org
- hash: 5b4f59236a9b950bcd5191b35d19125f60cfb9e1a1e1aa2e4f914b6745dde9df
- hash: 68fec379f2ae76c3d2ce913f7be650cea1d06990
- hash: 5761bd63da03686fc480245da7bd1e9f
- hash: 4f1773a1228e2c009cbcf61e9e550e01
- hash: 2aa47fb23074e8ae776a369f9e28d1a2f6e70739
- hash: 17aae57cf6255c7eb169bf62ea67376d9708976eb7831f8cdd0ea38bdcb37dc4
- hash: bc61ef6d7ad9ee878028f24d50e9dcf6d7d88bf2
- hash: 26b2da88cb95b98b46bb985f67f76154
- hash: 2fdfdd13a0c548bb68c9d5aa8599a9265d4659da3e237fe7a42ac6ac06b9a06a
- hash: 3c181f642e24c28602a87be7f195e2f3d1ffa30b37e20f5121d99f88b22ab80e
- url: https://almacensantangel.com/wp-includes/assets/YourSSA_Documents_0000000676152_05_187_2026_Document_0000000676152.rar
- domain: 0zbqnac1t4dv2t2wuodv1m.com
- domain: digital-magicians.com
- domain: fiusyevr.live
- ip: 89.34.90.99
- domain: fvxcuvuyte.live
- hash: 63bfd6567f4c704e8ed6530f5cdd704e
- hash: 080fdb73a6bbc99625c2190730257d1e54723952
- hash: 3f31aee0948d16f8d64bf6bec69a4331099993e502b11bfc56b2c0112024489d
- hash: 59ad96dd3b4d5f10a5c53bbd465446e52dc7701a4ac633632f762bf1336d3347
- hash: 66dbe675480dc229e5b3ab8ad74207f73486e64e57805074f784bb2e01bcb865
- hash: 6dbd6f9f2fa636c16ac4fa81418b68a604424861b9650dd9c4f2b0ba6f67d6ac
- hash: 7887e919555fb5948c217556ba149392a72982b1bc427d3db779db9dcbf09ee8
- hash: a6fb779be35592fb0ff624a8f8e12ab3cafe7bcfc312cd98263814db7fb01e02
- hash: c46e907886e2158cbc453e767183aecf07887b5ac8848f19684451883d69f5f0
- hash: c4e93449453cf67c5d5605bb8f425207a738a242fdb432d720acc32faa74926c
- hash: c5b1e9aafc8f2b4ab05effc00fd43f3114b9ef1d592a086c952793ac4e299809
- url: http://faeytrdeaw.gu.cc
- url: http://figyuyrqwr.gu.cc
- url: http://fiusyevr.live
- url: http://fuaytrwese.love
- url: http://hfyuayustrv.gu.cc
- url: http://hsahyteiows.gu.cc
- url: http://jaiydteds.love
- url: http://jsiruytrawey.gu.cc
- url: http://kawosyetw.gu.cc
- url: http://kawuuterta.gu.cc
- url: http://laiwutrencr.gu.cc
- url: http://lasiduutfe.gu.cc
- url: http://lisiutegrm.live
- url: http://maisytawe.gu.cc
- url: http://mksfuuerwo.live
- url: http://ncduuyese.live
- url: http://nciyeyrawoe.gu.cc
- url: http://nviuawusye.gu.cc
- url: http://nvsieyrrawe.gu.cc
- url: http://paiwudyea.love
- url: http://pmcjsuyraw.gu.cc
- url: http://qeuasytua.love
- url: http://svuatwea.love
- url: http://syfiaydytea.live
- url: http://viuyeyrwqs.gu.cc
- url: http://vusuydryt.love
- url: http://xkcifgieusr.gu.cc
- url: http://xnbscuya.love
- url: http://xuastyrdqk.love
- url: http://yicoweytcbtw.gu.cc
- url: https://digital-magicians.com/photo295825092412.zip?_r=ea623202
- url: https://fvxcuvuyte.live
- url: https://hsauyeet.live
- url: https://kdsuyrse.live
- url: https://oakwusya.love
- domain: fuaytrwese.love
- domain: hsauyeet.live
- domain: jaiydteds.love
- domain: kdsuyrse.live
- domain: lisiutegrm.live
- domain: mksfuuerwo.live
- domain: ncduuyese.live
- domain: oakwusya.love
- domain: paiwudyea.love
- domain: qeuasytua.love
- domain: svuatwea.love
- domain: syfiaydytea.live
- domain: vusuydryt.love
- domain: xnbscuya.love
- domain: xuastyrdqk.love
Unpacking "Cruciferra": An Analysis of a Sophisticated Crypter Service
Description
Cruciferra is a sophisticated crypter service utilized by multiple unrelated cybercriminal threat clusters to deliver remote access trojans and infostealers. Written in Mono, it employs extensive defense-evasion capabilities including indirect system calls, API unhooking, BYOVD-based EDR tampering, privilege escalation, and customized Process Ghosting for payload execution. The service features over 90 variations of cryptographic functions to obfuscate data and payloads, complicating static analysis and signature-based detection. Cruciferra was first advertised in fall 2025 with pricing tiers ranging from $450 to $2000 monthly. It has been observed in campaigns delivering various malware families including zgRAT, AgentTesla, AsyncRAT, XLoader, XWorm, Phantom Stealer, Formbook, and Remcos, primarily targeting financial services, healthcare, and government entities through opportunistic email-based attacks.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Cruciferra is a malware-as-a-service crypter platform written in Mono that facilitates delivery of multiple remote access trojans and infostealers by diverse cybercriminal clusters. It incorporates extensive defense-evasion capabilities including indirect system calls, API unhooking, BYOVD-based EDR tampering, privilege escalation, and customized process ghosting for payload execution. The service uses over 90 cryptographic function variants to obfuscate data and payloads, hindering static analysis and signature-based detection. Advertised since fall 2025 with pricing from $450 to $2000 monthly, Cruciferra has been linked to campaigns distributing malware such as zgRAT, AgentTesla, AsyncRAT, XLoader, XWorm, Phantom Stealer, Formbook, and Remcos. These campaigns primarily target financial services, healthcare, and government entities through opportunistic email phishing attacks. There is no indication of a software vulnerability or patch; this is a threat actor tool facilitating malware delivery.
Potential Impact
Cruciferra enables cybercriminals to evade detection and deliver a variety of remote access trojans and information stealers effectively. Its advanced obfuscation and defense-evasion techniques complicate detection by security products, increasing the risk of successful compromise of targeted organizations in financial, healthcare, and government sectors. The service's availability as malware-as-a-service lowers the barrier for multiple unrelated threat actors to conduct sophisticated attacks. However, there are no known exploits in the wild targeting software vulnerabilities, as Cruciferra itself is a malicious tool rather than a vulnerability.
Mitigation Recommendations
As Cruciferra is a malware service rather than a software vulnerability, no patches or official fixes exist. Defenders should focus on detecting and blocking phishing emails and payloads associated with the malware families distributed via Cruciferra. Employing advanced endpoint detection and response solutions capable of identifying behavior consistent with process ghosting, API unhooking, and EDR tampering may help mitigate infection risk. Monitoring threat intelligence sources for indicators related to Cruciferra campaigns is recommended. There is no vendor patch or remediation applicable to this threat.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://www.proofpoint.com/us/blog/threat-insight/unpacking-cruciferra-analysis-sophisticated-crypter-service"]
- Adversary
- TA4922
- Pulse Id
- 6a5dec09c0c4b7d2a00d7b2c
- Threat Score
- null
Indicators of Compromise
Hash
| Value | Description | Copy |
|---|---|---|
hash09bedbf7a41e0f8dabe4f41d331db58373ce15b2e9204540873a1884f38bdde1 | — | |
hash5b4f59236a9b950bcd5191b35d19125f60cfb9e1a1e1aa2e4f914b6745dde9df | — | |
hash68fec379f2ae76c3d2ce913f7be650cea1d06990 | — | |
hash5761bd63da03686fc480245da7bd1e9f | — | |
hash4f1773a1228e2c009cbcf61e9e550e01 | — | |
hash2aa47fb23074e8ae776a369f9e28d1a2f6e70739 | — | |
hash17aae57cf6255c7eb169bf62ea67376d9708976eb7831f8cdd0ea38bdcb37dc4 | — | |
hashbc61ef6d7ad9ee878028f24d50e9dcf6d7d88bf2 | — | |
hash26b2da88cb95b98b46bb985f67f76154 | — | |
hash2fdfdd13a0c548bb68c9d5aa8599a9265d4659da3e237fe7a42ac6ac06b9a06a | — | |
hash3c181f642e24c28602a87be7f195e2f3d1ffa30b37e20f5121d99f88b22ab80e | — | |
hash63bfd6567f4c704e8ed6530f5cdd704e | — | |
hash080fdb73a6bbc99625c2190730257d1e54723952 | — | |
hash3f31aee0948d16f8d64bf6bec69a4331099993e502b11bfc56b2c0112024489d | — | |
hash59ad96dd3b4d5f10a5c53bbd465446e52dc7701a4ac633632f762bf1336d3347 | — | |
hash66dbe675480dc229e5b3ab8ad74207f73486e64e57805074f784bb2e01bcb865 | — | |
hash6dbd6f9f2fa636c16ac4fa81418b68a604424861b9650dd9c4f2b0ba6f67d6ac | — | |
hash7887e919555fb5948c217556ba149392a72982b1bc427d3db779db9dcbf09ee8 | — | |
hasha6fb779be35592fb0ff624a8f8e12ab3cafe7bcfc312cd98263814db7fb01e02 | — | |
hashc46e907886e2158cbc453e767183aecf07887b5ac8848f19684451883d69f5f0 | — | |
hashc4e93449453cf67c5d5605bb8f425207a738a242fdb432d720acc32faa74926c | — | |
hashc5b1e9aafc8f2b4ab05effc00fd43f3114b9ef1d592a086c952793ac4e299809 | — |
Domain
| Value | Description | Copy |
|---|---|---|
domainalmacensantangel.com | — | |
domaingatuso.duckdns.org | — | |
domain0zbqnac1t4dv2t2wuodv1m.com | — | |
domaindigital-magicians.com | — | |
domainfiusyevr.live | — | |
domainfvxcuvuyte.live | — | |
domainfuaytrwese.love | — | |
domainhsauyeet.live | — | |
domainjaiydteds.love | — | |
domainkdsuyrse.live | — | |
domainlisiutegrm.live | — | |
domainmksfuuerwo.live | — | |
domainncduuyese.live | — | |
domainoakwusya.love | — | |
domainpaiwudyea.love | — | |
domainqeuasytua.love | — | |
domainsvuatwea.love | — | |
domainsyfiaydytea.live | — | |
domainvusuydryt.love | — | |
domainxnbscuya.love | — | |
domainxuastyrdqk.love | — |
Url
| Value | Description | Copy |
|---|---|---|
urlhttps://almacensantangel.com/wp-includes/assets/YourSSA_Documents_0000000676152_05_187_2026_Document_0000000676152.rar | — | |
urlhttp://faeytrdeaw.gu.cc | — | |
urlhttp://figyuyrqwr.gu.cc | — | |
urlhttp://fiusyevr.live | — | |
urlhttp://fuaytrwese.love | — | |
urlhttp://hfyuayustrv.gu.cc | — | |
urlhttp://hsahyteiows.gu.cc | — | |
urlhttp://jaiydteds.love | — | |
urlhttp://jsiruytrawey.gu.cc | — | |
urlhttp://kawosyetw.gu.cc | — | |
urlhttp://kawuuterta.gu.cc | — | |
urlhttp://laiwutrencr.gu.cc | — | |
urlhttp://lasiduutfe.gu.cc | — | |
urlhttp://lisiutegrm.live | — | |
urlhttp://maisytawe.gu.cc | — | |
urlhttp://mksfuuerwo.live | — | |
urlhttp://ncduuyese.live | — | |
urlhttp://nciyeyrawoe.gu.cc | — | |
urlhttp://nviuawusye.gu.cc | — | |
urlhttp://nvsieyrrawe.gu.cc | — | |
urlhttp://paiwudyea.love | — | |
urlhttp://pmcjsuyraw.gu.cc | — | |
urlhttp://qeuasytua.love | — | |
urlhttp://svuatwea.love | — | |
urlhttp://syfiaydytea.live | — | |
urlhttp://viuyeyrwqs.gu.cc | — | |
urlhttp://vusuydryt.love | — | |
urlhttp://xkcifgieusr.gu.cc | — | |
urlhttp://xnbscuya.love | — | |
urlhttp://xuastyrdqk.love | — | |
urlhttp://yicoweytcbtw.gu.cc | — | |
urlhttps://digital-magicians.com/photo295825092412.zip?_r=ea623202 | — | |
urlhttps://fvxcuvuyte.live | — | |
urlhttps://hsauyeet.live | — | |
urlhttps://kdsuyrse.live | — | |
urlhttps://oakwusya.love | — |
Ip
| Value | Description | Copy |
|---|---|---|
ip89.34.90.99 | — |
Threat ID: 6a5e02712a4a8d5989efa0af
Added to database: 07/20/2026, 11:11:45 UTC
Last enriched: 07/20/2026, 11:31:02 UTC
Last updated: 07/21/2026, 01:36:15 UTC
Views: 12
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.