The record
Written from the 1 report below. Nothing here is unsourced.
- Security researchers at Proofpoint have found that a China-linked cybercrime group and several unrelated criminal clusters are using a malware-obfuscation service called Cruciferra in phishing attacks against Indian and U.S. organizations.
- The group used income tax-themed emails targeting Indian taxpayers, tax professionals, and corporate finance teams to deliver remote access trojans and information stealers such as Agent Tesla, Remcos, and XWorm.
- Cruciferra, sold on the cybercrime underground for $450 to $2,000 a month, uses advanced evasion techniques like Process Ghosting and driver-based tampering to bypass security tools.
- Campaigns mainly hit financial services, healthcare, government, education, and manufacturing sectors, with hundreds to thousands of phishing messages per campaign.
What to watch next
- Whether Indian tax-themed campaigns linked to TA4922/Silver Fox continue beyond early June 2026
- Further research from Seqrite Labs under its Operation DragonReturn tracking
- New malware families or sectors being targeted via the Cruciferra service
Coverage1
1 report
English national1
All filed from India
Named India · United States · China · U.S. Social Security Administration · Windows · China-linked cybercrime group · Chris Wakelin · Cruciferra · Cyderes Howler Cell · Georgi Mladenov · Kyle Cucci · Proofpoint · Seqrite Labs
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
