www.infosecurity-magazine.com 7/20/2026, 3:30:53 PM · external

Cruciferra Crypter Powers Malware Evasion with Ghosting Tactics

Cruciferra Crypter Powers Malware Evasion with Ghosting Tactics
CyberSIXT Evidence Panel
Primary Source proofpoint.com
Threat Actor
🇨🇳 TA4922

THE article discusses the Cruciferra crypter, a service used by various cyber-criminal groups to cloak malware and evade detection. It details the advanced techniques utilized by Cruciferra, including process ghosting and kernel driver abuse, which help obscure malicious activity from security software. Launched on dark web forums in late 2025, the crypter supports multiple malware types, including AsyncRAT and XWorm, and operates on a tiered subscription model ranging from $450 to $2000 monthly.

Proofpoint highlighted the method of DLL side-loading and a complex encryption mechanism that employs over 90 distinct cipher routines. They also traced multiple campaigns back to the Chinese-speaking group TA4922, which used various deceptive lures in their attacks.

View Primary Source Via www.infosecurity-magazine.com

Article by CyberSIXT