The late-2023 PureRAT v0.3.8B build used an in-memory PE loader component protected with SmartAssembly-protected PureCrypter.
PureCrypter
PureCrypter is a C# malware-as-a-service loader and payload-protection framework active since at least 2021.
PureCrypter
Family profile
PureCrypter is a C# malware-as-a-service loader and payload-protection framework active since at least 2021. Marketed by the developer known as PureCoder (also called PureTeam), it is part of a commercial criminal toolset that includes PureRAT, PureLogs, BlueLoader, PureMiner, and PureClipper. PureCrypter is used to deliver unrelated second-stage malware, including information stealers, remote-access trojans, cryptominers, ransomware, and other commodity payloads.
PureCrypter commonly uses a staged downloader-and-injector design: an initial component retrieves a protected injector, which decrypts, unpacks, and executes or injects the final payload. Payload protection has included byte reversal, compression, symmetric encryption, resource-based storage, obfuscation, and benign-looking multimedia or image disguises. The injector supports multiple process-injection techniques, with process hollowing frequently observed. It can also create mutexes, establish Windows persistence, identify installed security products, perform debugger, sandbox, virtualization, display, and username checks, patch or bypass defensive telemetry mechanisms, and attempt to add Microsoft Defender exclusions or elevate privileges.
PureCrypter has been observed in phishing-driven and trojanized or cracked-software infection chains, as well as in compromises of exposed MS-SQL servers. It has been used by multiple criminal operators, including activity associated with the Mallox ransomware ecosystem, APT-C-36, and campaigns targeting Russian and South American organizations. Its modular, configurable design enables affiliates to use it as an evasive execution layer for payloads such as AgentTesla, RedLine, Formbook, SnakeKeylogger, AsyncRAT, Raccoon, Mars Stealer, PureMiner, PureLogs, PureRAT, and Mallox. PureCrypter targets Windows systems.
Capabilities
- Defense Evasion
- Persistence
- Privilege Escalation
- Process Injection
- Reconnaissance
Samples
Recent samples
1 sandbox sample in the Derp library, newest 1 shown
Reported operators
Threat actors
6 named in public reportingAPT-C-36 has utilized well known malware including the Packer-as-a-Service HeartCrypt, PureCrypter, and open-source RATs such as Remcos.
The payloads dropped through MS-SQL exploitation correspond to PureCrypter... This third-party payload is the Mallox ransomware.
While they still leverage classic droppers like PureCrypter and Rust-based loaders running Donut shellcode, they have added a potent new tool to their arsenal: PowerLoader.
PureCrypter malware has been observed distributing multiple RATs and information stealers. It is a .NET-based executable, obfuscated with SmartAssembly...
"...drop DarkTrack RAT via PureCrypter."
MITRE ATT&CK
PureCrypter in ATT&CK
60 distinct techniquesTechniques
60 techniquesReporting
Research mentioning PureCrypter
Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix | Huntress
Attackers abused ChatGPT Custom GPT pages branded as “Plus 5.6” and promoted them through sponsored Google Search results to impersonate a legitimate ChatGPT model. Victims were redirected to a fake backup domain hosting a Google Sites page styled as ChatGPT and Cloudflare verification prompts; the ClickFix lure instructed them to run PowerShell, silently installing a malicious MSI and a sophisticated remote-access trojan (RAT). Huntress handled at least 40 incidents tied to the Google Sites domain, including two confirmed infections originating from Custom GPT lures, and observed replacement lures after the original was removed. The campaign used signed third-party software for DLL sideloading and layered persistence. An initial variant abused Canon-signed CaptureOnTouch components, concealed its loader in a WAV file, and created Run-key and scheduled-task persistence labeled “Canon Configuration Reader.” A second variant preserved the RAT framework but used Stardock-signed DeElevate64.exe, a modified DeElevator64.dll, and a NuGet package carrier, establishing persistence as “Stardock DeElevation Tool.” Organizations should treat sponsored AI-tool search results and browser verification prompts that require shell commands as high-risk social-engineering activity.
Inside Two Multi-Stage Attack Chains Hiding Behind Job Offers - Malware News - Malware Analysis, News and Indicators
Two recruitment-themed malware campaigns use decoy job documents to deliver multi-stage, memory-resident implants after a single click. One campaign distributes a ZIP archive containing a renamed WinWord.exe that DLL-side-loads a malicious component to deploy PureRAT/ResolverRAT; researchers assess its infrastructure and tradecraft as overlapping with the Vietnam-nexus PXA Stealer criminal cluster. The other disguises an LNK shortcut as a PDF, invokes mshta.exe, and retrieves a custom native implant that decrypts and reflectively maps its DLL payload in memory. The second operation has not been attributed to a known threat actor. Both chains reduce Windows telemetry and analysis visibility through sandbox-evasion measures and Task Scheduler COM-based persistence rather than schtasks.exe, while providing attackers remote-access capability. The PureRAT campaign adds scheduled tasks, WMI event subscriptions, COM hijacking, and mirrored staging directories that can restore removed artifacts. The activity follows prior reporting on job-offer social engineering used to deploy Pure-family malware, including PureHVNC and PureRAT-linked tooling, and shows the continued use of this ecosystem alongside heavily obfuscated loaders and persistence mechanisms.
Inside Two Multi-Stage Attack Chains Hiding Behind Job Offers
Still Circling: Blind Eagle's Toolkit Keeps Evolving
Blind Eagle, also tracked as TAG-144, APT-C-36, and linked by some researchers to Red Akodon, continued targeting organizations across South America with a sustained emphasis on Colombian government entities at the local, municipal, and federal levels. Researchers described multi-stage intrusion chains using spearphishing, including compromised Colombian government email accounts, to deliver commodity and cracked remote access trojans through exposed Apache staging servers, dynamic DNS infrastructure, and legitimate internet services used for payload staging. The group has remained active since at least 2018, blending credential theft, financial crime, and surveillance-oriented collection against public-sector targets. Recent activity shows the actor refining rather than replacing its established toolkit. Investigators observed VBScript-to-PowerShell delivery chains, steganography to conceal payloads in image files, a new JavaScript stage with custom AES-based string obfuscation, an AutoIt3 RunPE loader fetched from raw.githubusercontent.com, and repeated use of the "Photo Studio" persistence disguise. The most significant upgrade was a new AsyncRAT variant, JC-46, which adds WNF-based process injection, custom Base28 encoding, HVNC support for banking fraud, browser profile cloning, and a bypass for Chrome App-Bound Encryption v20, while the group continued reusing VPN-linked command-and-control infrastructure and familiar dynamic DNS patterns.