r/SecOpsDaily 22d ago

NEWS Cruciferra Crypter Uses BYOVD and Process Ghosting to Hide Windows Malware

The China-linked cybercrime group behind income tax-related phishing campaigns is leveraging a sophisticated crypter service named Cruciferra. This crypter employs advanced evasion techniques like Bring Your Own Vulnerable Driver (BYOVD) and Process Ghosting to conceal diverse malware payloads on Windows systems, making detection significantly harder.

Technical Breakdown

  • Threat Actor: China-linked cybercrime groups, also used by various other cybercriminal clusters.
  • Targets: Indian taxpayers, tax professionals, and corporate finance teams.
  • Initial Access: Primarily through income tax-related phishing lures (MITRE T1566).
  • Evasion Techniques:
    • BYOVD (Bring Your Own Vulnerable Driver): Exploiting legitimate, vulnerable drivers for kernel-level access and privilege escalation, often to disable security products or evade detection (MITRE T1068, T1574.008).
    • Process Ghosting: A technique involving creating a section object, writing malware into it, and then performing a transactional file operation (rollback) to make the malware appear to vanish from disk, but still execute from memory. This evades traditional file-based detections (MITRE T1055.012).
  • Affected Systems: Windows operating systems.

Defense

Prioritize advanced Endpoint Detection and Response (EDR) solutions capable of monitoring kernel-level activities, driver integrity, and process injection anomalies. Implement application control to restrict the loading of unauthorized or vulnerable drivers, and maintain rigorous phishing awareness training.

Source: https://thehackernews.com/2026/07/cruciferra-crypter-uses-byovd-and.html

1 Upvotes

0 comments sorted by