Cruciferra: The Malware-Hiding Service Fuelling Attacks on Indian Taxpayers

A China-linked group is using a paid tool called Cruciferra to smuggle remote-access malware onto Windows machines, with tax-themed phishing emails as the way in.

ThreatVectr Newsdesk· 4 min read
Photoreal news-editorial overhead shot of a darkened open-plan European office at night, glowing monitors showing abstract email interfaces and red alert indica
Share

Key points

  • A China-linked cybercrime group is using tax-themed phishing emails to target Indian taxpayers, accountants and company finance teams.
  • The gang hides its malware using a paid service called Cruciferra, according to research by Proofpoint.
  • Cruciferra is a crypter, a tool that scrambles malware so antivirus software cannot recognise it.
  • Multiple unrelated criminal crews are paying for Cruciferra to deliver remote-access trojans, malware that hands attackers full control of a victim's computer.
  • The technique uses two advanced tricks known as BYOVD and process ghosting to bypass Windows defences.

A China-linked criminal group has been caught running tax-themed phishing attacks against people in India, and it is paying for a specialist service to keep its malware invisible to antivirus tools.

The service is called Cruciferra. In plain terms, it is a crypter: a piece of software that wraps other malware in layers of disguise so security products cannot spot it. Think of it as a laundry service for computer viruses.

The findings come from a new analysis by security firm Proofpoint, reported first by The Hacker News.

Who is being targeted?

Indian taxpayers, tax professionals and corporate finance staff. The attackers send emails dressed up as income tax notices, the kind of message an accountant or payroll clerk would open without thinking twice.

Once someone clicks, the malware installs quietly in the background. The victim sees nothing unusual. The attackers gain remote control of the machine, which on a finance team's laptop can mean access to bank logins, tax filings, payroll data and internal company systems.

What is Cruciferra and why does it matter?

Cruciferra is a paid tool that criminals rent to hide their malware. Proofpoint says several unrelated criminal crews are all using it, which is why the same evasion tricks keep showing up across otherwise unconnected attacks.

The tool's job is to deliver remote access trojans, malware that gives an attacker the same control over your PC as if they were sitting at the keyboard.

Two techniques stand out.

The first is BYOVD, short for Bring Your Own Vulnerable Driver. Attackers install a legitimate but flawed Windows driver, a small piece of trusted software that talks to hardware, and then abuse its known weakness to switch off antivirus protections from the inside.

The second is process ghosting. This lets malware run on a computer while leaving almost no trace that it was ever launched, because the file it started from has already been deleted by the time Windows notices.

Both tricks are designed to defeat the defences most companies rely on.

What does this look like in practice?

Detail What we know
Attacker origin China-linked cybercrime group
Victims Indian taxpayers, tax pros, corporate finance teams
Lure Fake income tax emails
Tool used Cruciferra crypter (rented service)
Payload Remote access trojans
Evasion tricks BYOVD and process ghosting

Cruciferra is not one gang's private weapon. It is a product sold into the criminal market, which means today's tax scam in Mumbai and tomorrow's payroll attack somewhere else may share the same fingerprint under the hood.

Should ordinary people worry?

If you file taxes in India or handle finances at work, treat unexpected tax emails with suspicion. Real tax authorities do not send attachments demanding you open them urgently. When in doubt, log in to the official tax portal directly through your browser rather than clicking any link.

Finance teams should assume that a convincing tax email will land in someone's inbox this filing season. The question is whether that person clicks.

Common questions

Is my antivirus enough to stop this?

Not on its own. Cruciferra is built specifically to slip past traditional antivirus. Layered defences, staff awareness and prompt patching all matter.

What is a remote access trojan?

It is malware that gives an attacker full remote control of your computer, letting them read files, capture passwords and watch what you type.

© 2026 Threat Vectr