A China-linked cybercrime operation targeting Indian taxpayers, tax professionals, and corporate finance teams has adopted Cruciferra, an advanced crypter service that uses multiple evasion techniques to bypass security controls. Proofpoint researchers discovered that the threat actors are deploying this sophisticated tool through phishing campaigns themed around income tax matters, successfully compromising victims across India's financial sector.
Cruciferra represents a significant evolution in malware obfuscation services available to cybercriminals. The crypter employs Bring Your Own Vulnerable Driver (BYOVD) attacks, which exploit legitimate but vulnerable signed drivers to gain kernel-level access and disable security software. Additionally, it uses process ghosting, a technique that loads malicious code into memory without writing it to disk in a way that traditional security tools can detect. These combined methods make detection extremely difficult for conventional antivirus and endpoint protection platforms.
Proofpoint's analysis reveals that Cruciferra is not exclusive to the China-linked group but has been adopted by multiple unrelated cybercriminal clusters. These diverse threat actors are using the service to deliver various types of remote access trojans and other malicious payloads. The crypter's availability as a service suggests a mature underground economy where sophisticated evasion tools are commoditized and accessible to a broad range of attackers, regardless of their technical capabilities.
The targeting of Indian financial professionals and taxpayers is particularly concerning given the sensitive nature of the data these individuals handle. Tax season provides an ideal cover for phishing campaigns, as recipients expect to receive communications about tax matters. The combination of social engineering tactics with advanced technical evasion creates a potent threat that can bypass both human vigilance and technical defenses.
Organizations should implement multiple defensive layers to protect against Cruciferra and similar threats. Security teams should enhance monitoring for suspicious driver installations and unusual kernel-level activity. Implementing application whitelisting can prevent unauthorized executables from running, while behavior-based detection systems can identify process ghosting attempts. Employee training on recognizing tax-themed phishing attempts remains critical, and organizations should verify the authenticity of any tax-related communications through independent channels before opening attachments or clicking links.
Source: https://thehackernews.com/2026/07/cruciferra-crypter-uses-byovd-and.html


