Cruciferra Crypter Uses Process Ghosting to Evade Detection
2026-07-20T20:52:21Z•010a1ddb750ba805f5dd9aea46732370f1244cf5cfd996b80bfa6149f6a65796
ENCFORGEai-enabled-exploitscalendar-abusecisa-urgent-patchcovert-c2credential-theftcrypterevilginxfortinetgigawipergoddamn-ransomwarehollowgraphjadepufferkernel-driverllm-abusemicrosoft-graphphishingpoisonxprocess-ghostingransomwarermm-lateral-movementsecure-boot-bypassuefivulnerabilitieswordpress-exploit
What happened
Multiple high-risk cyber developments: a new Cruciferra crypter uses process ghosting and custom ciphers to hide payloads; HollowGraph malware leverages Microsoft 365 calendars and Microsoft Graph APIs for covert C2; and JadePuffer actors deployed ENCFORGE ransomware designed to destruct AI model artifacts. Researchers and threat actors are increasingly using AI/LLMs to develop exploits (including a WordPress exploit built with OpenAI models), while phishing and credential-based attacks remain dominant entry vectors (Evilginx forks exposed; Lua loader disguised as TrueType file; eCard lures to
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- infosecurity_magazine
- Record identifier
- 010a1ddb750ba805f5dd9aea46732370f1244cf5cfd996b80bfa6149f6a65796
- Enrichment time
- 2026-07-20T20:52:21Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.