Skip to content

PureRAT

PureRAT is a .NET-based remote access trojan associated with the PureCoder malware ecosystem and used in multiple criminal intrusion chains.

Profile source: Mallory opens in a new tab

PureRAT

Family profile

PureRAT is a .NET-based remote access trojan associated with the PureCoder malware ecosystem and used in multiple criminal intrusion chains. It provides interactive control over compromised Windows systems and has been observed with capabilities including hidden VNC or remote desktop control, webcam and microphone access, keylogging, command execution, reverse proxying, screenshot capture, window monitoring, code injection, and plugin-based expansion. Some observed variants and modules also target browser data, session material, cryptocurrency wallets and wallet extensions, and other user data, blurring the line between remote access tooling and information theft.

Operationally, PureRAT is commonly delivered through multi-stage loaders and fileless or memory-resident execution chains. Reported delivery patterns include phishing and spearphishing lures, malicious LNK-based chains, ClickFix social engineering, WebDAV-delivered payloads, and DLL sideloading. Several campaigns used PowerShell, reflective .NET assembly loading, steganographic payload storage in PNG images, encrypted resource blobs, and process hollowing into legitimate signed processes to reduce on-disk artifacts and evade detection. Anti-analysis and defense-evasion behaviors documented across campaigns include virtual machine checks, UAC bypass, obfuscation with .NET Reactor, delayed configuration decryption, and use of trusted binaries for execution.

PureRAT has appeared in campaigns targeting hospitality organizations, hotel staff, Mexican users through government-themed lures, and Russian organizations across sectors including education, construction, consulting, manufacturing, engineering, retail, e-commerce, government, finance, energy, and diplomatic entities. It has been linked to activity clusters and delivery operations involving ClickFix infrastructure, DonutLoader, DlrtyGames, and phishing-led intrusion sets such as Fluffy Wolf, and it has also been observed alongside other PureCoder offerings including PureLogs, BlueLoader, and PureCrypter. Historical naming confusion has led some detections to label related traffic or samples as zgRAT, PureHVNC, or ResolverRAT, but PureRAT is a distinct malware family with its own remote-access feature set.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Dll Sideloading
  • Exfiltration
  • Keylogging
  • Persistence
  • Post Exploitation
  • Process Injection
  • Reconnaissance

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Jul 23, 2026
Last activity
Jul 29, 2026
Feed role
C2
Host form
27 IP / 0 hostnames

Leading locations

  • HK13
  • US8
  • DE2
  • FR2
  • SG1
  • SI1

Leading providers

  • Antbox Networks Limited5
  • Netsec Limited5
  • 12651980 CANADA INC.3
  • SonderCloud Limited3
  • 1337 Services GmbH2
  • Stellar Group SAS2

Infrastructure traits

  • Hosting 27

Samples

Recent associated samples

Reported operators

Threat actors

3 named in public reporting
Fluffy Wolf

These scripts systematically deploy the final payloads, which include the notorious Pay2Key ransomware, the PureLogs information stealer, and the PureRAT trojan.

REF1695

However, instead of the promised software, a series of loaders installs a malicious toolkit including CNB Bot, PureRAT, and SilentCryptoMiner.

Greedy Sponge

Credential Theft and Remote Access Surge as AllaKore, PureRAT, and Hijack Loader Proliferate

MITRE ATT&CK

PureRAT in ATT&CK

77 distinct techniques

Techniques

77 techniques
T1123 Audio Capture T1090.003 Multi-hop Proxy T1059.003 Windows Command Shell T1055 Process Injection T1125 Video Capture T1056.001 Keylogging T1219 Remote Access Tools T1204.002 Malicious File T1620 Reflective Code Loading T1113 Screen Capture T1027.013 Encrypted/Encoded File T1005 Data from Local System T1036.002 Right-to-Left Override T1547.001 Registry Run Keys / Startup Folder T1053.005 Scheduled Task T1119 Automated Collection T1573 Encrypted Channel T1055.012 Process Hollowing T1539 Steal Web Session Cookie T1555.003 Credentials from Web Browsers T1041 Exfiltration Over C2 Channel T1140 Deobfuscate/Decode Files or Information T1036.007 Double File Extension T1555 Credentials from Password Stores T1036 Masquerading T1566 Phishing T1053 Scheduled Task/Job T1497.003 Time Based Checks T1548.002 Bypass User Account Control T1106 Native API T1115 Clipboard Data T1218 System Binary Proxy Execution T1027.003 Steganography T1574.001 DLL T1560.001 Archive via Utility T1027.007 Dynamic API Resolution T1059.007 JavaScript T1571 Non-Standard Port T1566.002 Spearphishing Link T1129 Shared Modules T1071 Application Layer Protocol T1059 Command and Scripting Interpreter T1497 Virtualization/Sandbox Evasion T1027.002 Software Packing T1105 Ingress Tool Transfer T1071.001 Web Protocols T1027 Obfuscated Files or Information T1059.006 Python T1056 Input Capture T1218.009 Regsvcs/Regasm T1560 Archive Collected Data T1566.001 Spearphishing Attachment T1059.010 AutoHotKey & AutoIT T1547.009 Shortcut Modification T1059.001 PowerShell T1204 User Execution T1082 System Information Discovery T1008 Fallback Channels T1059.005 Visual Basic T1003 OS Credential Dumping T1104 Multi-Stage Channels T1033 System Owner/User Discovery T1047 Windows Management Instrumentation T1021.002 SMB/Windows Admin Shares T1083 File and Directory Discovery T1021.006 Windows Remote Management T1055.002 Portable Executable Injection T1112 Modify Registry T1087.001 Local Account T1027.009 Embedded Payloads T1497.001 System Checks T1566.003 Spearphishing via Service T1127 Trusted Developer Utilities Proxy Execution T1070.004 File Deletion T1562.001 Disable or Modify Tools T1564.001 Hidden Files and Directories T1090 Proxy

Reporting

Research mentioning PureRAT

Jul 21
Cyber Security News

One Security Alert Exposed a GenAI-Powered Malware Factory Containing More Than 1,000 Attack Files

Researchers uncovered an exposed attacker-controlled server that revealed the full workflow behind a WebDAV phishing operation delivering malware through Windows shortcut and signed-binary execution chains. The infrastructure held 1,048 artifacts including phishing lures, testing notes, admin-panel files, delivery analytics, and documentation that suggested the operator used generative AI tooling to build content and test matrices at scale. The most active campaign impersonated Mexico’s CURP identity-record service through the typosquatted domain gobf[.]mx, used a WebDAV share on onedrive[.]cv, and abused CVE-2025-33053, a Windows working-directory hijack flaw previously linked to Stealth Falcon activity, to launch a disguised payload posing as a PDF report. The recovered files showed the actor testing 59 .url shortcut variants against multiple signed Windows binaries, likely adapting after the original iediagcmd.exe technique became less effective on Windows 11 24H2. One infection chain delivered a fileless in-memory .NET infostealer that exfiltrated data to 77.110.127.205, while a second campaign, tracked as DlrtyGames, used a 7-Zip SFX dropper, DLL sideloading via a signed Ubisoft binary, IDAT-carried payloads, process hollowing, and persistence to deploy the modular PureRAT malware communicating with 23.94.252.228:57666. Delivery logs from the exposed Simba Service panel recorded 77,098 requests from 3,892 unique IPs across 101 countries over roughly 5.5 days, with activity heavily concentrated in Mexico.

Jul 21
Cyberveille

Labo de livraison de malware via WebDAV exposé : 1 000 artefacts et usage de GenAI découverts | CyberVeille

Jul 20
Trojan Killer News

Fake CURP WebDAV Lures Drop In-Memory Stealer

Jul 20
The Hacker News

Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign

Jul 20
Rapid7

Inside an Exposed Malware Delivery Lab: OPSEC Failures Behind a WebDAV Phishing Operation

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.