malware-log.hatenablog.com • 2h
Cruciferra Crypter: Advanced EDR Evasion and Multi-RAT Deployment by TA4922
Cruciferra is a Crypter-as-a-Service (CaaS) launched in Autumn 2025, utilized by threat actor TA4922 and other affiliates to bypass modern Endpoint Detection and Response (EDR) systems. The tool employs advanced decryption routines and active EDR disablement to create operational blind spots on compromised hosts. Once security software is neutralized, Cruciferra deploys high-impact Remote Access Trojans (RATs), specifically AsyncRAT, Remcos, XWorm, and Agent Tesla. This shift toward specialized, high-efficacy evasion tooling has resulted in dozens of distinct malware campaigns with high success rates against current defensive solutions, facilitating espionage and data theft.