The China-linked cybercrime group behind tax-themed phishing lures targeting Indian taxpayers and corporate finance teams has deployed a sophisticated crypter service called Cruciferra. According to Proofpoint, Cruciferra is written in Mono and employs advanced evasion techniques including indirect system calls, API unhooking, bring-your-own-vulnerable-driver (BYOVD) attacks, privilege escalation, persistence mechanisms, and a custom Process Ghosting implementation to execute payloads while minimizing forensic artifacts.
Cruciferra has been advertised on the cybercrime underground as the ‘most lethal crypter’ for $450 to $2,000 per month since fall 2025. It supports polymorphic encryption routines derived from established cryptographic algorithms, complicating static analysis and signature-based detection. The service has been used to distribute commodity malware families such as Agent Tesla, AsyncRAT, DarkCloud Stealer, Formbook, Phantom Stealer, Remcos RAT, Snake Keylogger, ValleyRAT, XLoader, XWorm, and zgRAT.
Campaigns leveraging Cruciferra use phishing as the primary initial access vector, targeting financial services, healthcare, government, education, and manufacturing sectors. One campaign attributed to Chinese-speaking actor TA4922 (overlapping with Silver Fox) uses tax-themed lures to deliver malware via ZIP files hosted on attacker-controlled landing pages. Four such campaigns were identified between April and early June 2026, tracked by Seqrite Labs as Operation DragonReturn. Other campaigns include emails impersonating the U.S. Social Security Administration to deliver XWorm and AdaptixC2 (May 2026), and hospitality-themed emails delivering zgRAT (late June 2026).
Cruciferra is executed via DLL side-loading and uses the GoFlyDrv.sys driver for BYOVD attacks to terminate security processes. It checks for administrator privileges and attempts UAC bypass via COM Elevation Moniker, establishes persistence via the registry key SoftwareMicrosoftWindowsCurrentVersionRun with value ‘putty’, and loads the final payload using Process Ghosting. Cruciferra also patches ZwQueryVirtualMemory hooks and tampers with NtManageHotPatch to hide file deletion and neutralize integrity checks.
CVEs: CVE-2026-50522
Attack groups: TA4922, Silver Fox
Malware: Cruciferra, Agent Tesla, AsyncRAT, DarkCloud Stealer, Formbook, Phantom Stealer, Remcos RAT, Snake Keylogger, ValleyRAT, XLoader, XWorm, zgRAT
Companies: Proofpoint, Seqrite Labs, Cyderes Howler Cell
Products: GoFlyDrv.sys
Original source: thehackernews.com