Skip to content
A crypter service used by multiple unrelated cyber-criminal groups has been documented cloaking commodity malware with process ghosting, kernel-driver abuse and more than 90 mix-and-match encryption routines. According to new research from Proofpoint published on July 20, the crypter, marketed as Cruciferra, was first offered for sale on the Exploit forum in autumn 2025 and now underpins dozens of...
Cruciferra Crypter Uses Process Ghosting to Evade Detection | Huntaegis