Pure is a Trojan malware family observed in financial fraud activity, particularly targeted invoice-fraud campaigns against organizations. According to the provided content, it was frequently used in 2025 attacks abusing electronic document management (EDM) systems, where fraudsters substituted invoice details to trick victims into transferring funds. The malware was also delivered through emails using accounting-related file names and abbreviations. Check Point describes a broader Pure malware family that includes PureRAT, PureHVNC RAT, PureCrypter, PureLogs, and PureCoder. The content states that Pure was heavily seen in the corporate segment in 2025, with 896,633 detections and more than 64,000 users attacked. High-confidence associations in the content are with corporate financial fraud and invoice-themed delivery; no additional technical IOCs are provided in the source material.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Trojan frequently used in 2025 attacks against organizations via electronic document management systems, often distributed through targeted emails with accounting-themed attachments to facilitate invoice fraud.
The Pure malware family includes various strains such as RATs, crypters, and stealers, used for remote access, credential theft, and obfuscation.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.