Last seven days
- First activity
- Sep 6, 2026
- Last activity
- Sep 12, 2026
- Feed role
- C2 / Distribution
- Host form
- 85 IP / 0 hostnames
PureRAT is a modular .NET remote-access trojan developed and sold by the PureCoder malware-as-a-service ecosystem.
Profile source: Mallory opens in a new tabPureRAT
PureRAT is a modular .NET remote-access trojan developed and sold by the PureCoder malware-as-a-service ecosystem. It has also been tracked under the historical names ResolverRAT and PureHVNC. PureRAT provides interactive control of compromised Windows systems through hidden VNC and remote-desktop functions, command execution, webcam and microphone access, real-time keylogging, reverse-proxy functionality, and code injection. Observed variants profile hosts and security products, capture screenshots and active-window information, and steal Chromium-browser data, cryptocurrency-wallet data, and data associated with selected desktop applications. Some plugin sets can monitor clipboard cryptocurrency addresses and substitute attacker-controlled addresses.
PureRAT commonly uses encrypted, protobuf-encoded command-and-control communications and can receive additional modules or tasks, including download-and-execute instructions. Campaigns have deployed it through phishing and recruitment, invoice, complaint, hospitality, and government-service lures, often using malicious archives, disguised executables or shortcuts, landing pages, and DLL side-loading. Operators have also used in-memory loading, process hollowing or injection, AMSI and ETW impairment, sandbox checks, and scheduled-task, Startup-folder, registry, WMI, or COM-based persistence. Documented activity includes financially motivated campaigns against Russian organizations, job seekers, hospitality organizations, accounting firms, and targets in Japan, Korea, Mexico, Europe, and Asia. Some PureRAT operations overlap with a Vietnam-nexus criminal cluster associated with PXA Stealer activity, while Fluffy Wolf has deployed PureRAT in phishing operations against Russian organizations.
C2 tracking
Derp observations, rolling seven-day window
Samples
08295c1247b7ce6dc020bfba5ba75540e3b5c98665ba99f2f73b37016811f47c 3610fcc54a204281b09095004f02b674cd75bdd83996a1428fdef85645eff3e1 91847a5075fd0e938f4aec3a23a4437c6445f4eefc201fa288e0d1513edf0561 aa8bf93029edf167b6eaa0cfbf2b60490da8f9e5788e871ffe9c363d45683988 f959a8494f2a1c4e11f346ae8e3099593f156be2a5c8010d1747e4466a11316a 565ebdbc3a1d3c26c7a81f89e560dbfc96b2e8cb8ad258184a4bf8ba2a903c00 13f867ba5f46eae93cf52215367a7136566f86274d77df49bb07057ff1358ec5 4c6024969b76ff86831a067038d0b3032eaa0da0ae4de749898c43c118328eb8 74c86e4ec19b386f5bffb0e8d6923ac1f0bdd99fa203809dbb0bfa49964383fa 5192ebca06dc2fe77ece481d57a91b7ac1d3fcaac6e7c9f2d7cdafb203d137bb Reported operators
Campaign 2 uses a multi-stage fake-installer chain to drop PureRAT v3.0.1; its C2 issued a download-and-execute task for an XMR mining payload.
in July 2025, eSentire reported an association between PureRAT, a remote access trojan (RAT) first advertised in January 2023, and GhostCrypt, a crypting service sold by an underground forum member of the same moniker, in an attack that impacted a public US accounting firm in May 2025.
These scripts systematically deploy the final payloads, which include the notorious Pay2Key ransomware, the PureLogs information stealer, and the PureRAT trojan.
Credential Theft and Remote Access Surge as AllaKore, PureRAT, and Hijack Loader Proliferate
MITRE ATT&CK
Reporting
Two recruitment-themed malware campaigns use decoy job documents to deliver multi-stage, memory-resident implants after a single click. One campaign distributes a ZIP archive containing a renamed WinWord.exe that DLL-side-loads a malicious component to deploy PureRAT/ResolverRAT; researchers assess its infrastructure and tradecraft as overlapping with the Vietnam-nexus PXA Stealer criminal cluster. The other disguises an LNK shortcut as a PDF, invokes mshta.exe, and retrieves a custom native implant that decrypts and reflectively maps its DLL payload in memory. The second operation has not been attributed to a known threat actor. Both chains reduce Windows telemetry and analysis visibility through sandbox-evasion measures and Task Scheduler COM-based persistence rather than schtasks.exe, while providing attackers remote-access capability. The PureRAT campaign adds scheduled tasks, WMI event subscriptions, COM hijacking, and mirrored staging directories that can restore removed artifacts. The activity follows prior reporting on job-offer social engineering used to deploy Pure-family malware, including PureHVNC and PureRAT-linked tooling, and shows the continued use of this ecosystem alongside heavily obfuscated loaders and persistence mechanisms.
Researchers uncovered an exposed attacker-controlled server that revealed the full workflow behind a WebDAV phishing operation delivering malware through Windows shortcut and signed-binary execution chains. The infrastructure held 1,048 artifacts including phishing lures, testing notes, admin-panel files, delivery analytics, and documentation that suggested the operator used generative AI tooling to build content and test matrices at scale. The most active campaign impersonated Mexico’s CURP identity-record service through the typosquatted domain gobf[.]mx, used a WebDAV share on onedrive[.]cv, and abused CVE-2025-33053, a Windows working-directory hijack flaw previously linked to Stealth Falcon activity, to launch a disguised payload posing as a PDF report. The recovered files showed the actor testing 59 .url shortcut variants against multiple signed Windows binaries, likely adapting after the original iediagcmd.exe technique became less effective on Windows 11 24H2. One infection chain delivered a fileless in-memory .NET infostealer that exfiltrated data to 77.110.127.205, while a second campaign, tracked as DlrtyGames, used a 7-Zip SFX dropper, DLL sideloading via a signed Ubisoft binary, IDAT-carried payloads, process hollowing, and persistence to deploy the modular PureRAT malware communicating with 23.94.252.228:57666. Delivery logs from the exposed Simba Service panel recorded 77,098 requests from 3,892 unique IPs across 101 countries over roughly 5.5 days, with activity heavily concentrated in Mexico.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.