Skip to content

PureCrypter

PureCrypter is a C# malware-as-a-service loader and payload-protection framework active since at least 2021.

PureCrypter

Family profile

PureCrypter is a C# malware-as-a-service loader and payload-protection framework active since at least 2021. Marketed by the developer known as PureCoder (also called PureTeam), it is part of a commercial criminal toolset that includes PureRAT, PureLogs, BlueLoader, PureMiner, and PureClipper. PureCrypter is used to deliver unrelated second-stage malware, including information stealers, remote-access trojans, cryptominers, ransomware, and other commodity payloads.

PureCrypter commonly uses a staged downloader-and-injector design: an initial component retrieves a protected injector, which decrypts, unpacks, and executes or injects the final payload. Payload protection has included byte reversal, compression, symmetric encryption, resource-based storage, obfuscation, and benign-looking multimedia or image disguises. The injector supports multiple process-injection techniques, with process hollowing frequently observed. It can also create mutexes, establish Windows persistence, identify installed security products, perform debugger, sandbox, virtualization, display, and username checks, patch or bypass defensive telemetry mechanisms, and attempt to add Microsoft Defender exclusions or elevate privileges.

PureCrypter has been observed in phishing-driven and trojanized or cracked-software infection chains, as well as in compromises of exposed MS-SQL servers. It has been used by multiple criminal operators, including activity associated with the Mallox ransomware ecosystem, APT-C-36, and campaigns targeting Russian and South American organizations. Its modular, configurable design enables affiliates to use it as an evasive execution layer for payloads such as AgentTesla, RedLine, Formbook, SnakeKeylogger, AsyncRAT, Raccoon, Mars Stealer, PureMiner, PureLogs, PureRAT, and Mallox. PureCrypter targets Windows systems.

Capabilities

  • Defense Evasion
  • Persistence
  • Privilege Escalation
  • Process Injection
  • Reconnaissance

Samples

Recent samples

1 sandbox sample in the Derp library, newest 1 shown

Reported operators

Threat actors

6 named in public reporting
REF1695

The late-2023 PureRAT v0.3.8B build used an in-memory PE loader component protected with SmartAssembly-protected PureCrypter.

APT-C-36

APT-C-36 has utilized well known malware including the Packer-as-a-Service HeartCrypt, PureCrypter, and open-source RATs such as Remcos.

8220 Gang

The payloads dropped through MS-SQL exploitation correspond to PureCrypter... This third-party payload is the Mallox ransomware.

Fluffy Wolf

While they still leverage classic droppers like PureCrypter and Rust-based loaders running Donut shellcode, they have added a potent new tool to their arsenal: PowerLoader.

PureCoder

PureCrypter malware has been observed distributing multiple RATs and information stealers. It is a .NET-based executable, obfuscated with SmartAssembly...

MITRE ATT&CK

PureCrypter in ATT&CK

60 distinct techniques

Techniques

60 techniques
T1685 Disable or Modify Tools T1614 System Location Discovery T1480.002 Mutual Exclusion T1573.001 Symmetric Cryptography T1573.002 Asymmetric Cryptography T1036.008 Masquerade File Type T1055 Process Injection T1036.005 Match Legitimate Resource Name or Location T1140 Deobfuscate/Decode Files or Information T1480 Execution Guardrails T1057 Process Discovery T1082 System Information Discovery T1102 Web Service T1027.013 Encrypted/Encoded File T1059.001 PowerShell T1518.001 Security Software Discovery T1673 Virtual Machine Discovery T1053.005 Scheduled Task T1564.003 Hidden Window T1027.016 Junk Code Insertion T1622 Debugger Evasion T1070.004 File Deletion T1547.001 Registry Run Keys / Startup Folder T1033 System Owner/User Discovery T1678 Delay Execution T1105 Ingress Tool Transfer T1588.001 Malware T1027 Obfuscated Files or Information T1497 Virtualization/Sandbox Evasion T1620 Reflective Code Loading T1218.004 InstallUtil T1036 Masquerading T1566 Phishing T1204.002 Malicious File T1547.004 Winlogon Helper DLL T1005 Data from Local System T1548.002 Bypass User Account Control T1047 Windows Management Instrumentation T1560 Archive Collected Data T1547.009 Shortcut Modification T1059.005 Visual Basic T1204 User Execution T1547 Boot or Logon Autostart Execution T1055.012 Process Hollowing T1059.003 Windows Command Shell T1070 Indicator Removal T1134 Access Token Manipulation T1027.002 Software Packing T1566.001 Spearphishing Attachment T1566.002 Spearphishing Link T1573 Encrypted Channel T1106 Native API T1055.004 Asynchronous Procedure Call T1059.006 Python T1574.001 DLL T1218.005 Mshta T1583.006 Web Services T1090.002 External Proxy T1665 Hide Infrastructure T1071.001 Web Protocols

Reporting

Research mentioning PureCrypter

Sep 28
Huntress

Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix | Huntress

Attackers abused ChatGPT Custom GPT pages branded as “Plus 5.6” and promoted them through sponsored Google Search results to impersonate a legitimate ChatGPT model. Victims were redirected to a fake backup domain hosting a Google Sites page styled as ChatGPT and Cloudflare verification prompts; the ClickFix lure instructed them to run PowerShell, silently installing a malicious MSI and a sophisticated remote-access trojan (RAT). Huntress handled at least 40 incidents tied to the Google Sites domain, including two confirmed infections originating from Custom GPT lures, and observed replacement lures after the original was removed. The campaign used signed third-party software for DLL sideloading and layered persistence. An initial variant abused Canon-signed CaptureOnTouch components, concealed its loader in a WAV file, and created Run-key and scheduled-task persistence labeled “Canon Configuration Reader.” A second variant preserved the RAT framework but used Stardock-signed DeElevate64.exe, a modified DeElevator64.dll, and a NuGet package carrier, establishing persistence as “Stardock DeElevation Tool.” Organizations should treat sponsored AI-tool search results and browser verification prompts that require shell commands as high-risk social-engineering activity.

Sep 10
Malware News

Inside Two Multi-Stage Attack Chains Hiding Behind Job Offers - Malware News - Malware Analysis, News and Indicators

Two recruitment-themed malware campaigns use decoy job documents to deliver multi-stage, memory-resident implants after a single click. One campaign distributes a ZIP archive containing a renamed WinWord.exe that DLL-side-loads a malicious component to deploy PureRAT/ResolverRAT; researchers assess its infrastructure and tradecraft as overlapping with the Vietnam-nexus PXA Stealer criminal cluster. The other disguises an LNK shortcut as a PDF, invokes mshta.exe, and retrieves a custom native implant that decrypts and reflectively maps its DLL payload in memory. The second operation has not been attributed to a known threat actor. Both chains reduce Windows telemetry and analysis visibility through sandbox-evasion measures and Task Scheduler COM-based persistence rather than schtasks.exe, while providing attackers remote-access capability. The PureRAT campaign adds scheduled tasks, WMI event subscriptions, COM hijacking, and mirrored staging directories that can restore removed artifacts. The activity follows prior reporting on job-offer social engineering used to deploy Pure-family malware, including PureHVNC and PureRAT-linked tooling, and shows the continued use of this ecosystem alongside heavily obfuscated loaders and persistence mechanisms.

Sep 10
Cyderes

Inside Two Multi-Stage Attack Chains Hiding Behind Job Offers

Jul 17
Levelblue Spiderlabs

Still Circling: Blind Eagle's Toolkit Keeps Evolving

Blind Eagle, also tracked as TAG-144, APT-C-36, and linked by some researchers to Red Akodon, continued targeting organizations across South America with a sustained emphasis on Colombian government entities at the local, municipal, and federal levels. Researchers described multi-stage intrusion chains using spearphishing, including compromised Colombian government email accounts, to deliver commodity and cracked remote access trojans through exposed Apache staging servers, dynamic DNS infrastructure, and legitimate internet services used for payload staging. The group has remained active since at least 2018, blending credential theft, financial crime, and surveillance-oriented collection against public-sector targets. Recent activity shows the actor refining rather than replacing its established toolkit. Investigators observed VBScript-to-PowerShell delivery chains, steganography to conceal payloads in image files, a new JavaScript stage with custom AES-based string obfuscation, an AutoIt3 RunPE loader fetched from raw.githubusercontent.com, and repeated use of the "Photo Studio" persistence disguise. The most significant upgrade was a new AsyncRAT variant, JC-46, which adds WNF-based process injection, custom Base28 encoding, HVNC support for banking fraud, browser profile cloning, and a bypass for Chrome App-Bound Encryption v20, while the group continued reusing VPN-linked command-and-control infrastructure and familiar dynamic DNS patterns.

Mar 31
Elastic Security Labs

Fake Installers to Monero: A Multi-Tool Mining Operation

Aug 26
Recorded Future

TAG-144’s Persistent Grip on South American Organizations