Skip to content

PureRAT

PureRAT is a modular .NET remote-access trojan developed and sold by the PureCoder malware-as-a-service ecosystem.

Profile source: Mallory opens in a new tab

PureRAT

Family profile

PureRAT is a modular .NET remote-access trojan developed and sold by the PureCoder malware-as-a-service ecosystem. It has also been tracked under the historical names ResolverRAT and PureHVNC. PureRAT provides interactive control of compromised Windows systems through hidden VNC and remote-desktop functions, command execution, webcam and microphone access, real-time keylogging, reverse-proxy functionality, and code injection. Observed variants profile hosts and security products, capture screenshots and active-window information, and steal Chromium-browser data, cryptocurrency-wallet data, and data associated with selected desktop applications. Some plugin sets can monitor clipboard cryptocurrency addresses and substitute attacker-controlled addresses.

PureRAT commonly uses encrypted, protobuf-encoded command-and-control communications and can receive additional modules or tasks, including download-and-execute instructions. Campaigns have deployed it through phishing and recruitment, invoice, complaint, hospitality, and government-service lures, often using malicious archives, disguised executables or shortcuts, landing pages, and DLL side-loading. Operators have also used in-memory loading, process hollowing or injection, AMSI and ETW impairment, sandbox checks, and scheduled-task, Startup-folder, registry, WMI, or COM-based persistence. Documented activity includes financially motivated campaigns against Russian organizations, job seekers, hospitality organizations, accounting firms, and targets in Japan, Korea, Mexico, Europe, and Asia. Some PureRAT operations overlap with a Vietnam-nexus criminal cluster associated with PXA Stealer activity, while Fluffy Wolf has deployed PureRAT in phishing operations against Russian organizations.

Capabilities

  • Credential Theft
  • Crypto Theft
  • Defense Evasion
  • Dll Sideloading
  • Exfiltration
  • Keylogging
  • Persistence
  • Post Exploitation
  • Process Injection
  • Reconnaissance
  • Session Hijacking

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Sep 6, 2026
Last activity
Sep 12, 2026
Feed role
C2 / Distribution
Host form
85 IP / 0 hostnames

Leading locations

  • HK23
  • US18
  • FR9
  • NL9
  • AU6
  • DE6
  • MA3
  • TR3
  • FI2
  • IT2
  • SG2
  • HU1

Leading providers

  • RouterHosting LLC8
  • Antbox Networks Limited7
  • 12651980 CANADA INC.5
  • CTG Server Limited5
  • Stellar Group SAS5
  • GLOBAL CONNECTIVITY SOLUTIONS LLP4

Infrastructure traits

  • Hosting 78

Samples

Recent associated samples

Reported operators

Threat actors

4 named in public reporting
REF1695

Campaign 2 uses a multi-stage fake-installer chain to drop PureRAT v3.0.1; its C2 issued a download-and-execute task for an XMR mining payload.

GhostCrypt

in July 2025, eSentire reported an association between PureRAT, a remote access trojan (RAT) first advertised in January 2023, and GhostCrypt, a crypting service sold by an underground forum member of the same moniker, in an attack that impacted a public US accounting firm in May 2025.

Fluffy Wolf

These scripts systematically deploy the final payloads, which include the notorious Pay2Key ransomware, the PureLogs information stealer, and the PureRAT trojan.

Greedy Sponge

Credential Theft and Remote Access Surge as AllaKore, PureRAT, and Hijack Loader Proliferate

MITRE ATT&CK

PureRAT in ATT&CK

88 distinct techniques

Techniques

88 techniques
T1562.001 Disable or Modify Tools T1573.002 Asymmetric Cryptography T1562.006 Indicator Blocking T1053.005 Scheduled Task T1546.015 Component Object Model Hijacking T1546.003 Windows Management Instrumentation Event Subscription T1620 Reflective Code Loading T1113 Screen Capture T1497.003 Time Based Checks T1027.013 Encrypted/Encoded File T1027 Obfuscated Files or Information T1564.001 Hidden Files and Directories T1518.001 Security Software Discovery T1140 Deobfuscate/Decode Files or Information T1082 System Information Discovery T1059.006 Python T1071.001 Web Protocols T1115 Clipboard Data T1070.004 File Deletion T1041 Exfiltration Over C2 Channel T1622 Debugger Evasion T1553.005 Mark-of-the-Web Bypass T1056.001 Keylogging T1132.001 Standard Encoding T1555.003 Credentials from Web Browsers T1105 Ingress Tool Transfer T1083 File and Directory Discovery T1204.002 Malicious File T1036.005 Match Legitimate Resource Name or Location T1059.001 PowerShell T1560 Archive Collected Data T1547.001 Registry Run Keys / Startup Folder T1005 Data from Local System T1566.002 Spearphishing Link T1036 Masquerading T1027.009 Embedded Payloads T1027.002 Software Packing T1059.003 Windows Command Shell T1071 Application Layer Protocol T1566 Phishing T1573 Encrypted Channel T1055 Process Injection T1566.001 Spearphishing Attachment T1218.004 InstallUtil T1219 Remote Access Tools T1059 Command and Scripting Interpreter T1123 Audio Capture T1125 Video Capture T1021.005 VNC T1090 Proxy T1090.003 Multi-hop Proxy T1036.002 Right-to-Left Override T1119 Automated Collection T1055.012 Process Hollowing T1539 Steal Web Session Cookie T1036.007 Double File Extension T1555 Credentials from Password Stores T1053 Scheduled Task/Job T1548.002 Bypass User Account Control T1106 Native API T1218 System Binary Proxy Execution T1027.003 Steganography T1574.001 DLL T1560.001 Archive via Utility T1027.007 Dynamic API Resolution T1059.007 JavaScript T1571 Non-Standard Port T1129 Shared Modules T1497 Virtualization/Sandbox Evasion T1056 Input Capture T1218.009 Regsvcs/Regasm T1059.010 AutoHotKey & AutoIT T1547.009 Shortcut Modification T1204 User Execution T1008 Fallback Channels T1059.005 Visual Basic T1003 OS Credential Dumping T1104 Multi-Stage Channels T1033 System Owner/User Discovery T1047 Windows Management Instrumentation T1021.002 SMB/Windows Admin Shares T1021.006 Windows Remote Management T1055.002 Portable Executable Injection T1112 Modify Registry T1087.001 Local Account T1497.001 System Checks T1566.003 Spearphishing via Service T1127 Trusted Developer Utilities Proxy Execution

Reporting

Research mentioning PureRAT

Sep 10
Malware News

Inside Two Multi-Stage Attack Chains Hiding Behind Job Offers - Malware News - Malware Analysis, News and Indicators

Two recruitment-themed malware campaigns use decoy job documents to deliver multi-stage, memory-resident implants after a single click. One campaign distributes a ZIP archive containing a renamed WinWord.exe that DLL-side-loads a malicious component to deploy PureRAT/ResolverRAT; researchers assess its infrastructure and tradecraft as overlapping with the Vietnam-nexus PXA Stealer criminal cluster. The other disguises an LNK shortcut as a PDF, invokes mshta.exe, and retrieves a custom native implant that decrypts and reflectively maps its DLL payload in memory. The second operation has not been attributed to a known threat actor. Both chains reduce Windows telemetry and analysis visibility through sandbox-evasion measures and Task Scheduler COM-based persistence rather than schtasks.exe, while providing attackers remote-access capability. The PureRAT campaign adds scheduled tasks, WMI event subscriptions, COM hijacking, and mirrored staging directories that can restore removed artifacts. The activity follows prior reporting on job-offer social engineering used to deploy Pure-family malware, including PureHVNC and PureRAT-linked tooling, and shows the continued use of this ecosystem alongside heavily obfuscated loaders and persistence mechanisms.

Sep 10
Cyderes

Inside Two Multi-Stage Attack Chains Hiding Behind Job Offers

Jul 21
Cyber Security News

One Security Alert Exposed a GenAI-Powered Malware Factory Containing More Than 1,000 Attack Files

Researchers uncovered an exposed attacker-controlled server that revealed the full workflow behind a WebDAV phishing operation delivering malware through Windows shortcut and signed-binary execution chains. The infrastructure held 1,048 artifacts including phishing lures, testing notes, admin-panel files, delivery analytics, and documentation that suggested the operator used generative AI tooling to build content and test matrices at scale. The most active campaign impersonated Mexico’s CURP identity-record service through the typosquatted domain gobf[.]mx, used a WebDAV share on onedrive[.]cv, and abused CVE-2025-33053, a Windows working-directory hijack flaw previously linked to Stealth Falcon activity, to launch a disguised payload posing as a PDF report. The recovered files showed the actor testing 59 .url shortcut variants against multiple signed Windows binaries, likely adapting after the original iediagcmd.exe technique became less effective on Windows 11 24H2. One infection chain delivered a fileless in-memory .NET infostealer that exfiltrated data to 77.110.127.205, while a second campaign, tracked as DlrtyGames, used a 7-Zip SFX dropper, DLL sideloading via a signed Ubisoft binary, IDAT-carried payloads, process hollowing, and persistence to deploy the modular PureRAT malware communicating with 23.94.252.228:57666. Delivery logs from the exposed Simba Service panel recorded 77,098 requests from 3,892 unique IPs across 101 countries over roughly 5.5 days, with activity heavily concentrated in Mexico.

Jul 21
Cyberveille

Labo de livraison de malware via WebDAV exposé : 1 000 artefacts et usage de GenAI découverts | CyberVeille

Jul 20
Trojan Killer News

Fake CURP WebDAV Lures Drop In-Memory Stealer

Jul 20
The Hacker News

Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign

Jul 20
Rapid7

Inside an Exposed Malware Delivery Lab: OPSEC Failures Behind a WebDAV Phishing Operation

Mar 31
Elastic Security Labs

Fake Installers to Monero: A Multi-Tool Mining Operation

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.