Last seven days
- First activity
- Jul 15, 2026
- Last activity
- Jul 20, 2026
- Feed role
- C2
- Host form
- 3 IP / 0 hostnames
PureRAT is a .NET-based remote access trojan (RAT) sold by the developer PureCoder and repeatedly observed in multi-stage, heavily obfuscated, largely fileless intrusion chains targeting Windows systems.
Profile source: Mallory opens in a new tabPureRAT
PureRAT is a .NET-based remote access trojan (RAT) sold by the developer PureCoder and repeatedly observed in multi-stage, heavily obfuscated, largely fileless intrusion chains targeting Windows systems. Reported delivery vectors include malicious LNK files, phishing archives, ClickFix and Booking-themed phishing aimed at hotel staff, fake software or ISO installers, malicious XLL files, and binder or loader chains such as DonutLoader and PowerLoader. Multiple reports describe PowerShell- and VBScript-based staging, steganographic concealment of payloads inside PNG images, in-memory assembly loading, .NET Reactor protection, TripleDES-decrypted resources, anti-VM checks for VMware and QEMU, UAC bypass via cmstp.exe, and process hollowing or RunPE into legitimate processes including msbuild.exe and CasPol.exe. PureRAT establishes persistence through scheduled tasks, HKCU\Software\Microsoft\Windows\CurrentVersion\Run, RunOnce entries, and Startup-folder shortcuts, and can gather host and security-product information, execute commands, download additional payloads, and support modular plugins including keylogging, remote desktop access, credential theft on demand, microphone/webcam monitoring, desktop image capture, active-window monitoring, and mouse/keyboard control. It has been linked in reporting to campaigns targeting the hospitality sector in Europe and Asia, Russian organizations across sectors including education, government, finance, energy, construction, consulting, manufacturing, retail, engineering, and e-commerce, and to broader cybercrime activity involving credential theft, follow-on fraud, cryptomining, and ransomware delivery. Associated activity and operators mentioned in the content include PureCoder, Fluffy Wolf, REF1695, and campaigns documented by Sekoia, Trellix, Microsoft, Elastic, BI.ZONE, Kaspersky, and Breakglass. High-confidence indicators mentioned in the content include crixup[.]com, instantservices1[.]ddnsguru[.]com, 178.16.52.58, smveo.com, admin.sm-veo.com, agent.sm-veo.com, wss://agent.sm-veo.com:8443/v1/ws, and observed use of ports including 1917, 4782, 56001, 56002, and 56003.
C2 tracking
Derp observations, rolling seven-day window
Samples
2fd3e4fed8a88f9aa00a921cbb6fb564aa64943b20fc512ce3eb134d5ebfd2d3 401b70e0313d7f6dd1fd444a8d61e25ae433a5944a2607405fe5ddbc9b8f7afc 65ba3988d38f83b9ee1f31cafa5bd37dc6b72279f5618aac94d71a904efa0cac b4a3205341b7d6eee7d8a810300a39960ac66c7fb89f585a06c6e1e921a49820 Reported operators
These scripts systematically deploy the final payloads, which include the notorious Pay2Key ransomware, the PureLogs information stealer, and the PureRAT trojan.
However, instead of the promised software, a series of loaders installs a malicious toolkit including CNB Bot, PureRAT, and SilentCryptoMiner.
Credential Theft and Remote Access Surge as AllaKore, PureRAT, and Hijack Loader Proliferate
MITRE ATT&CK
Reporting
Rapid7 identified the final payload as a .NET-based PureRAT. Its modules supported keylogging, screenshots, window monitoring, browser wallet-extension targeting, Chrome data access, and command-and-control communication.
Based on our observations, the final RAT payload in both chains was identified as .NET-based PureRAT.
Malware / Outils # TonRAT (rat) PureRat (rat) Wacatac (other)
Booking-themed phishing aimed at hotel staff has been a recurring pattern, including ClickFix campaigns that dropped PureRAT to steal Booking.com logins.
Microsoft Defender Antivirus Trojan:Win32/PureRat
These scripts systematically deploy the final payloads, which include the notorious Pay2Key ransomware, the PureLogs information stealer, and the PureRAT trojan.
Один из них представляет собой биндер для доставки известных бэкдоров и стилеров, включая PureRAT.
Расшифрованная нагрузка — это бэкдор PureRAT, описанный в одной из наших прошлых статей.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.