Last seven days
- First activity
- Jul 23, 2026
- Last activity
- Jul 29, 2026
- Feed role
- C2
- Host form
- 27 IP / 0 hostnames
PureRAT is a .NET-based remote access trojan associated with the PureCoder malware ecosystem and used in multiple criminal intrusion chains.
Profile source: Mallory opens in a new tabPureRAT
PureRAT is a .NET-based remote access trojan associated with the PureCoder malware ecosystem and used in multiple criminal intrusion chains. It provides interactive control over compromised Windows systems and has been observed with capabilities including hidden VNC or remote desktop control, webcam and microphone access, keylogging, command execution, reverse proxying, screenshot capture, window monitoring, code injection, and plugin-based expansion. Some observed variants and modules also target browser data, session material, cryptocurrency wallets and wallet extensions, and other user data, blurring the line between remote access tooling and information theft.
Operationally, PureRAT is commonly delivered through multi-stage loaders and fileless or memory-resident execution chains. Reported delivery patterns include phishing and spearphishing lures, malicious LNK-based chains, ClickFix social engineering, WebDAV-delivered payloads, and DLL sideloading. Several campaigns used PowerShell, reflective .NET assembly loading, steganographic payload storage in PNG images, encrypted resource blobs, and process hollowing into legitimate signed processes to reduce on-disk artifacts and evade detection. Anti-analysis and defense-evasion behaviors documented across campaigns include virtual machine checks, UAC bypass, obfuscation with .NET Reactor, delayed configuration decryption, and use of trusted binaries for execution.
PureRAT has appeared in campaigns targeting hospitality organizations, hotel staff, Mexican users through government-themed lures, and Russian organizations across sectors including education, construction, consulting, manufacturing, engineering, retail, e-commerce, government, finance, energy, and diplomatic entities. It has been linked to activity clusters and delivery operations involving ClickFix infrastructure, DonutLoader, DlrtyGames, and phishing-led intrusion sets such as Fluffy Wolf, and it has also been observed alongside other PureCoder offerings including PureLogs, BlueLoader, and PureCrypter. Historical naming confusion has led some detections to label related traffic or samples as zgRAT, PureHVNC, or ResolverRAT, but PureRAT is a distinct malware family with its own remote-access feature set.
C2 tracking
Derp observations, rolling seven-day window
Samples
Reported operators
These scripts systematically deploy the final payloads, which include the notorious Pay2Key ransomware, the PureLogs information stealer, and the PureRAT trojan.
However, instead of the promised software, a series of loaders installs a malicious toolkit including CNB Bot, PureRAT, and SilentCryptoMiner.
Credential Theft and Remote Access Surge as AllaKore, PureRAT, and Hijack Loader Proliferate
MITRE ATT&CK
Reporting
Researchers uncovered an exposed attacker-controlled server that revealed the full workflow behind a WebDAV phishing operation delivering malware through Windows shortcut and signed-binary execution chains. The infrastructure held 1,048 artifacts including phishing lures, testing notes, admin-panel files, delivery analytics, and documentation that suggested the operator used generative AI tooling to build content and test matrices at scale. The most active campaign impersonated Mexico’s CURP identity-record service through the typosquatted domain gobf[.]mx, used a WebDAV share on onedrive[.]cv, and abused CVE-2025-33053, a Windows working-directory hijack flaw previously linked to Stealth Falcon activity, to launch a disguised payload posing as a PDF report. The recovered files showed the actor testing 59 .url shortcut variants against multiple signed Windows binaries, likely adapting after the original iediagcmd.exe technique became less effective on Windows 11 24H2. One infection chain delivered a fileless in-memory .NET infostealer that exfiltrated data to 77.110.127.205, while a second campaign, tracked as DlrtyGames, used a 7-Zip SFX dropper, DLL sideloading via a signed Ubisoft binary, IDAT-carried payloads, process hollowing, and persistence to deploy the modular PureRAT malware communicating with 23.94.252.228:57666. Delivery logs from the exposed Simba Service panel recorded 77,098 requests from 3,892 unique IPs across 101 countries over roughly 5.5 days, with activity heavily concentrated in Mexico.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.