
Tax and SSA Phish Push Cruciferra Malware Loader
Researchers report multiple real-world email phishing campaigns that used tax and government-benefit themes to trick people into downloading malware. The…
Proofpoint observed real phishing campaigns using government-themed lures to trick people into downloading ZIP files that install malware. The campaigns used a “crypter” service called Cruciferra to help common remote-access and data-stealing malware evade detection. Financial services, healthcare, and government organizations were frequently targeted.
Proofpoint identified multiple phishing campaigns that used a crypter service called Cruciferra to disguise remote-access and information-stealing malware from detection tools. The campaigns did not rely on a single lure. Instead, attackers used several distinct pretexts to reach victims across different sectors:
In each case, the goal was the same: get the recipient to download a ZIP archive or visit an attacker-controlled site that kicked off the infection chain, ultimately installing malware such as AsyncRAT, XWorm, or zgRAT.
These campaigns leaned on believable, high-stakes themes rather than purely technical tricks. A tax notice, a benefits message, or a customer complaint all create a sense of obligation or urgency that pushes people to act quickly instead of scrutinizing the request. Financial services, healthcare, and government organizations were frequently targeted, likely because staff in these sectors regularly handle official notices, benefits paperwork, and customer correspondence, making these lures feel routine.
Once a recipient clicked through and downloaded the archive, Cruciferra's evasion techniques were designed to help the resulting malware avoid detection, meaning the social engineering step, not the malware's sophistication, was the point of failure that mattered most.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
Cruciferra is a crypter service that attackers use to help remote-access and information-stealing malware evade detection after a victim opens a malicious file, using evasion features like BYOVD and Process Ghosting.
Campaigns impersonated government tax authorities with fake Income Tax Department notifications, the U.S. Social Security Administration, and hospitality complaints about bed bugs, all designed to get recipients to download ZIP archives.
Financial services, healthcare, and government organizations were frequently targeted in these campaigns.
The infection chains led to remote-access and information-stealing malware including AsyncRAT, XWorm, and zgRAT after victims downloaded the malicious archives.
You get an email: “Income Tax Department Notification – Action Required.” Looks official, government logo, bold red deadline. You click. It opens a lookalike tax portal that tells you: download a ZIP file to see your notice. That ZIP runs Cruciferra, quietly loading malware like AsyncRAT or XWorm on your machine. Proofpoint’s seen this over and over: fake Income Tax Department emails, Social Security "Important Notice" messages, even bed bug complaint themes, all pushing you to a site or ZIP download that starts the Cruciferra infection chain. If any government-branded email tells you to download a ZIP or file, don’t click it, go to the official site yourself and log in there instead.

Researchers report multiple real-world email phishing campaigns that used tax and government-benefit themes to trick people into downloading malware. The…

This threat trend report describes multiple real-world APT campaigns that rely on social engineering (job offers, fake recruiters, code reviews, and…

A Russia-aligned espionage group sent specially crafted HTML emails that could compromise vulnerable Zimbra webmail servers just by being opened or previewed,…

Researchers linked DigiCert’s April 2026 breach to a GoldenEyeDog sub-group that tricked support staff into running a malicious file delivered through a…

North Korea-linked BlueNoroff is using fake Zoom and Microsoft Teams meeting pages shared from hijacked trusted contacts (often via Telegram) to trick victims…

A June 2026 financial-sector threat report describes real phishing emails that used business-looking themes (e.g., money transfers, receipts, voicemail) to…