PureHVNC is a Windows remote access trojan centered on hidden VNC functionality that gives an operator covert, real-time control of an infected desktop. It is commonly deployed in financially motivated crimeware campaigns and is frequently clustered with other commodity malware families such as AsyncRAT, DcRAT, XWorm, VenomRAT, PureLogs, zgRAT, STXRAT, and PureRAT. Observed operations show it being used both as a standalone remote-control payload and as part of broader multi-stage intrusion chains that combine credential theft, persistence, process injection, and large-scale data exfiltration.
The malware’s core role is stealthy remote desktop access and screen interaction. Reported campaigns attribute to PureHVNC capabilities including hidden VNC control, screen capture, persistent access, and in some cases credential theft from browsers and email clients. It has also appeared in intrusion chains where companion malware harvested saved credentials and where PureHVNC provided the operator with interactive post-compromise access. In mature operations, PureHVNC has been launched through trusted Windows utilities, injected into benign processes, and paired with anti-idle mechanisms to keep remote sessions active.
Delivery has been observed through multiple initial-access paths. PureHVNC has repeatedly been distributed via malspam using business-themed lures such as orders, invoices, requests, documents, notices, quotations, payments, purchases, reservations, offers, shipments, and bank transfers, including sustained Italian-language campaigns targeting organizations in Italy. It has also been delivered through ClickFix-style social engineering, including fake verification or booking-themed pages that trick users into executing PowerShell, and through trojanized software packages that abuse DLL side-loading. Several campaigns used layered staging with script loaders, batch files, portable Python runtimes, Donut shellcode, and reflective or APC-style injection into processes such as explorer.exe or notepad.exe before handing off to the final RAT.
PureHVNC is strongly associated with evasive tradecraft. Documented chains include DLL side-loading, in-memory execution, process injection, abuse of legitimate Windows binaries, and persistence via Startup artifacts or Run-key mechanisms. In larger delivery ecosystems such as SERPENTINE#CLOUD, PureHVNC was one of several RAT families repeatedly repackaged through polymorphic Python loaders, Cloudflare Tunnel-hosted staging infrastructure, WebDAV delivery, AMSI and WLDP bypasses, and anti-forensic cleanup routines. Other observed campaigns used packers and crypters, including Ygfumkl and Brute Ratel C4 wrappers, to conceal or inject the PureHVNC stage.
Victimology in observed reporting spans business users, hospitality-sector staff, German-speaking organizations, UK-linked targets, and Italian organizations reached through localized malspam. The overall pattern is consistent with financially motivated cybercrime rather than espionage: operators use commodity MaaS-style tooling, rotate staging infrastructure aggressively, and combine PureHVNC with stealers and loaders to support credential theft, remote control, and follow-on monetization.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
22 distinct techniques documented for this family, organized by ATT&CK tactic.
2026-04-10 11:04+ > Repeated PowerShell Invoke-Expression chains (non-interactive); dynamic .NET recompilation; multiple STXRAT beacon renewals
The batch stagers are the initial execution layer. 29 .bat files recovered across six evidence directories deduplicate to 13 unique templates in four categories.
Each stager also downloads Shoopify.bat , PWS.vbs , and pws1.vbs into the Startup folder... Anti-idle scripts Deployed by all download stagers to the Startup folder
The ZIP contains a Python runtime and one or more loader scripts. Each loader decrypts embedded shellcode, and that shellcode bootstraps the .NET Common Language Runtime (CLR) to load the actual payload.
allocate RWX memory, write shellcode via WriteProcessMemory ... ctypes.windll.kernel32.VirtualProtect(... 0x40, # PAGE_EXECUTE_READWRITE ... )
Below we see the subjects used in the various campaigns divided by day and type of malware.
By combining user-assisted PowerShell execution, staged payload delivery, DLL side-loading, persistence mechanisms, and in-memory process injection...
Injection technique: create a suspended notepad.exe , allocate RWX memory, write shellcode via WriteProcessMemory , queue an APC, resume the thread... Instead of notepad.exe, the loaders now create a suspended explorer.exe and use Early Bird APC injection
Wave 4/5 introduces the deepest nesting observed in the campaign. The Nov19 Donut instances deliver native x64 PE wrappers instead of .NET assemblies directly... Layer 2: Kramer decode (hex -> unicode shift -> rotation -> RC4 -> base64)
By combining user-assisted PowerShell execution, staged payload delivery, DLL side-loading, persistence mechanisms, and in-memory process injection...
Injection technique: create a suspended notepad.exe , allocate RWX memory, write shellcode via WriteProcessMemory , queue an APC, resume the thread... Instead of notepad.exe, the loaders now create a suspended explorer.exe and use Early Bird APC injection
The campaign also highlights increasing abuse of legitimate Windows utilities and trusted binaries to evade conventional security controls.
PowerShell: csc.exe compiles ClassLibrary17.dll from %TEMP%; InstallUtil.exe /u launches PureHVNC component; C2: 176.65.144[.]46:65001
If detected, downloads abb11.zip (OBKS-only, Avast-safe profile). If not, downloads quz11.zip (full WBKS + BKSNO deployment).
Checks for AvastUI.exe and AVGUI.exe via tasklist. If detected, downloads abb11.zip (OBKS-only, Avast-safe profile). If not, downloads quz11.zip
159 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
37 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
PureHVNC2
Password stealer distributed via malspam campaigns targeting Italy; observed in campaigns themed around orders and requests.
A malware family observed in malspam campaigns targeting Italy; the report groups it among password-stealer families.
Password stealer distributed via malspam campaigns targeting Italy during the week of 2026-06-15 to 2026-06-21.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.