A China-linked cybercrime group has used a malware delivery service called Cruciferra in phishing campaigns targeting Indian taxpayers, tax professionals and corporate finance teams, according to a technical analysis by Proofpoint. The company said the crypter has also been used by unrelated threat actors to distribute remote access trojans and information stealers.
KEY FACTS
- Tool Cruciferra is a crypter service written in Mono.
- Targets Campaigns have focused on financial services, healthcare, government, education and manufacturing.
- Pricing The service was advertised for $450 to $2,000 a month.
- Delivery Attackers used phishing, DLL side-loading and a staging server to deliver payloads.
- Defense evasion The malware used BYOVD tampering, privilege escalation and Process Ghosting.
Proofpoint said Cruciferra first appeared for sale in fall 2025. The report said it has been used to deliver commodity malware including Agent Tesla, AsyncRAT, DarkCloud Stealer, Formbook, Phantom Stealer, Remcos RAT, Snake Keylogger, ValleyRAT, XLoader, XWorm and zgRAT.
Researchers said the service supports custom encryption routines that vary across samples, which complicates static analysis and signature-based detection. It also uses indirect system calls, API and Import Address Table unhooking, and a customized form of Process Ghosting to reduce forensic traces.
One campaign attributed to a Chinese-speaking actor known as TA4922 used tax-themed lures to send victims to attacker-controlled landing pages hosting ZIP files. Four such campaigns were identified between April and early June 2026, and other activity included fake U.S. Social Security Administration emails and late June messages themed around bed bugs and guest complaints.
The report said Cruciferra checks for administrator rights, tries to bypass User Account Control, and writes to the Windows Run registry key with the value putty to persist after reboot. It also uses the GoFlyDrv.sys driver in a BYOVD attack to terminate security processes.
WHY IT MATTERS
The findings show how a single crypter service can be reused across different malware families and campaign themes while making detection harder for defenders. That raises the risk of broader compromise across sectors that rely on email and Windows endpoints.

