Cruciferra Crypter Uses BYOVD and Process Ghosting to Hide Windows Malware
Summary
A China-linked cybercrime group is utilizing a sophisticated crypter service named Cruciferra to deliver Windows malware. This crypter employs Bring Your Own Vulnerable Driver (BYOVD) and process ghosting techniques to evade detection by security software. Multiple threat clusters have been observed using Cruciferra, indicating its broad adoption in the cybercrime landscape.
IFF Assessment
The use of advanced evasion techniques like BYOVD and process ghosting by a cybercrime group signifies a growing challenge for defenders in detecting and mitigating malware.
Defender Context
Defenders should be aware of the Cruciferra crypter and its evasion tactics, particularly BYOVD and process ghosting. This indicates a need for enhanced endpoint detection and response (EDR) capabilities that can identify these advanced stealth techniques and monitor driver loading and process manipulation more closely.