Cruciferra Crypter: Advanced EDR Evasion and Multi-RAT Deployment by TA4922
Cruciferra is a Crypter-as-a-Service (CaaS) launched in Autumn 2025, utilized by threat actor TA4922 and other affiliates to bypass modern Endpoint Detection and Response (EDR) systems. The tool employs advanced decryption routines and active EDR disablement to create operational blind spots on compromised hosts. Once security software is neutralized, Cruciferra deploys high-impact Remote Access Trojans (RATs), specifically AsyncRAT, Remcos, XWorm, and Agent Tesla. This shift toward specialized, high-efficacy evasion tooling has resulted in dozens of distinct malware campaigns with high success rates against current defensive solutions, facilitating espionage and data theft.
Remcos RAT Deployment via Multi-Stage .NET Steganography in GST Phishing Campaigns
A sophisticated, financially motivated cybercrime campaign is targeting the Indian financial and taxation ecosystem by impersonating the Government of India's GST department. The attack leverages high-pressure social engineering via spoofed emails regarding "GST refund applications" to trick taxpayers into downloading malicious archives. Once executed, the malware initiates a multi-stage .NET infection chain utilizing advanced evasion techniques, including bitmap steganography for payload concealment and in-memory execution via .NET reflection to maintain a fileless footprint. The operation culminates in the deployment of Remcos RAT, granting attackers full remote command and control (C2) for credential theft, surveillance, and data exfiltration, while employing architecture-specific execution paths to ensure successful deployment across x86 and x64 systems.