Cruciferra Crypter Uses Process Ghosting to Evade Detection

2026-07-20T20:52:21Z010a1ddb750ba805f5dd9aea46732370f1244cf5cfd996b80bfa6149f6a65796
ENCFORGEai-enabled-exploitscalendar-abusecisa-urgent-patchcovert-c2credential-theftcrypterevilginxfortinetgigawipergoddamn-ransomwarehollowgraphjadepufferkernel-driverllm-abusemicrosoft-graphphishingpoisonxprocess-ghostingransomwarermm-lateral-movementsecure-boot-bypassuefivulnerabilitieswordpress-exploit

What happened

Multiple high-risk cyber developments: a new Cruciferra crypter uses process ghosting and custom ciphers to hide payloads; HollowGraph malware leverages Microsoft 365 calendars and Microsoft Graph APIs for covert C2; and JadePuffer actors deployed ENCFORGE ransomware designed to destruct AI model artifacts. Researchers and threat actors are increasingly using AI/LLMs to develop exploits (including a WordPress exploit built with OpenAI models), while phishing and credential-based attacks remain dominant entry vectors (Evilginx forks exposed; Lua loader disguised as TrueType file; eCard lures to

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
infosecurity_magazine
Record identifier
010a1ddb750ba805f5dd9aea46732370f1244cf5cfd996b80bfa6149f6a65796
Enrichment time
2026-07-20T20:52:21Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.