Skip to content
Malware family

PureRAT

PureRAT is a .NET-based remote access trojan (RAT) sold by the developer PureCoder and repeatedly observed in multi-stage, heavily obfuscated, largely fileless intrusion chains targeting Windows systems.

Profile source: Mallory opens in a new tab

PureRAT

Family profile

PureRAT is a .NET-based remote access trojan (RAT) sold by the developer PureCoder and repeatedly observed in multi-stage, heavily obfuscated, largely fileless intrusion chains targeting Windows systems. Reported delivery vectors include malicious LNK files, phishing archives, ClickFix and Booking-themed phishing aimed at hotel staff, fake software or ISO installers, malicious XLL files, and binder or loader chains such as DonutLoader and PowerLoader. Multiple reports describe PowerShell- and VBScript-based staging, steganographic concealment of payloads inside PNG images, in-memory assembly loading, .NET Reactor protection, TripleDES-decrypted resources, anti-VM checks for VMware and QEMU, UAC bypass via cmstp.exe, and process hollowing or RunPE into legitimate processes including msbuild.exe and CasPol.exe. PureRAT establishes persistence through scheduled tasks, HKCU\Software\Microsoft\Windows\CurrentVersion\Run, RunOnce entries, and Startup-folder shortcuts, and can gather host and security-product information, execute commands, download additional payloads, and support modular plugins including keylogging, remote desktop access, credential theft on demand, microphone/webcam monitoring, desktop image capture, active-window monitoring, and mouse/keyboard control. It has been linked in reporting to campaigns targeting the hospitality sector in Europe and Asia, Russian organizations across sectors including education, government, finance, energy, construction, consulting, manufacturing, retail, engineering, and e-commerce, and to broader cybercrime activity involving credential theft, follow-on fraud, cryptomining, and ransomware delivery. Associated activity and operators mentioned in the content include PureCoder, Fluffy Wolf, REF1695, and campaigns documented by Sekoia, Trellix, Microsoft, Elastic, BI.ZONE, Kaspersky, and Breakglass. High-confidence indicators mentioned in the content include crixup[.]com, instantservices1[.]ddnsguru[.]com, 178.16.52.58, smveo.com, admin.sm-veo.com, agent.sm-veo.com, wss://agent.sm-veo.com:8443/v1/ws, and observed use of ports including 1917, 4782, 56001, 56002, and 56003.

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Jul 15, 2026
Last activity
Jul 20, 2026
Feed role
C2
Host form
3 IP / 0 hostnames

Leading locations

  • DE1
  • LU1
  • US1

Leading providers

  • Ghosty Networks LLC1
  • H4Y Technologies LLC1
  • OC NETWORKS LIMITED1

Infrastructure traits

  • Hosting 3

Samples

Recent associated samples

Reported operators

Threat actors

3 named in public reporting
Fluffy Wolf

These scripts systematically deploy the final payloads, which include the notorious Pay2Key ransomware, the PureLogs information stealer, and the PureRAT trojan.

REF1695

However, instead of the promised software, a series of loaders installs a malicious toolkit including CNB Bot, PureRAT, and SilentCryptoMiner.

Greedy Sponge

Credential Theft and Remote Access Surge as AllaKore, PureRAT, and Hijack Loader Proliferate

MITRE ATT&CK

PureRAT in ATT&CK

63 distinct techniques

Techniques

63 techniques
T1059.007 JavaScript T1571 Non-Standard Port T1566.002 Spearphishing Link T1204.002 Malicious File T1547.001 Registry Run Keys / Startup Folder T1027.007 Dynamic API Resolution T1129 Shared Modules T1071 Application Layer Protocol T1059 Command and Scripting Interpreter T1219 Remote Access Tools T1497 Virtualization/Sandbox Evasion T1027.002 Software Packing T1573 Encrypted Channel T1105 Ingress Tool Transfer T1071.001 Web Protocols T1620 Reflective Code Loading T1140 Deobfuscate/Decode Files or Information T1027 Obfuscated Files or Information T1059.006 Python T1566 Phishing T1056 Input Capture T1113 Screen Capture T1055 Process Injection T1218.009 Regsvcs/Regasm T1560 Archive Collected Data T1059.003 Windows Command Shell T1566.001 Spearphishing Attachment T1059.010 AutoHotKey & AutoIT T1547.009 Shortcut Modification T1059.001 PowerShell T1204 User Execution T1082 System Information Discovery T1218 System Binary Proxy Execution T1008 Fallback Channels T1059.005 Visual Basic T1003 OS Credential Dumping T1056.001 Keylogging T1053.005 Scheduled Task T1106 Native API T1104 Multi-Stage Channels T1033 System Owner/User Discovery T1047 Windows Management Instrumentation T1021.002 SMB/Windows Admin Shares T1083 File and Directory Discovery T1021.006 Windows Remote Management T1055.002 Portable Executable Injection T1112 Modify Registry T1087.001 Local Account T1055.012 Process Hollowing T1027.009 Embedded Payloads T1027.003 Steganography T1548.002 Bypass User Account Control T1053 Scheduled Task/Job T1497.001 System Checks T1566.003 Spearphishing via Service T1036 Masquerading T1560.001 Archive via Utility T1127 Trusted Developer Utilities Proxy Execution T1070.004 File Deletion T1562.001 Disable or Modify Tools T1564.001 Hidden Files and Directories T1574.001 DLL T1090 Proxy

Reporting

Research mentioning PureRAT

Jul 20
Trojan Killer News

Fake CURP WebDAV Lures Drop In-Memory Stealer

Rapid7 identified the final payload as a .NET-based PureRAT. Its modules supported keylogging, screenshots, window monitoring, browser wallet-extension targeting, Chrome data access, and command-and-control communication.

Jul 20
Rapid7

Inside an Exposed Malware Delivery Lab: OPSEC Failures Behind a WebDAV Phishing Operation

Based on our observations, the final RAT payload in both chains was identified as .NET-based PureRAT.

Jun 30
Cyberveille

Campagne Photo ZIP ciblant l'hôtellerie : implant Node.js et persistance duale via registre | CyberVeille

Malware / Outils # TonRAT (rat) PureRat (rat) Wacatac (other)

Jun 26
The Hacker News

Microsoft Warns of Photo ZIP Phishing Campaign Targeting Hotels with Node.js Implant

Booking-themed phishing aimed at hotel staff has been a recurring pattern, including ClickFix campaigns that dropped PureRAT to steal Booking.com logins.

Jun 25
Microsoft General

Photo ZIP campaign targeting hospitality industry delivers Node.js implant for persistent access | Microsoft Security Blog

Microsoft Defender Antivirus Trojan:Win32/PureRat

Jun 16
Security Online Info

Fluffy Wolf Phishing Attacks Push PowerLoader Malware

These scripts systematically deploy the final payloads, which include the notorious Pay2Key ransomware, the PureLogs information stealer, and the PureRAT trojan.

Jun 1
Xakep

Хакеры атакуют организации в РФ с помощью инструмента для пентестов Ravage - Хакер

Один из них представляет собой биндер для доставки известных бэкдоров и стилеров, включая PureRAT.

May 29
Securelist Ru

Вузы морского профиля атакует неизвестная группа | Securelist

Расшифрованная нагрузка — это бэкдор PureRAT, описанный в одной из наших прошлых статей.

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.