PureCrypter is a commercial .NET crypter/loader in the PureCoder malware-as-a-service ecosystem. It is described as a .NET-based executable, often obfuscated with SmartAssembly or ConfuserEx, and functions as a secondary dropper/resource loader that decrypts embedded payloads, decompresses them, loads them in memory via .NET reflection, and invokes them. Multiple reports specifically describe PureCrypter as a .NET 3DES loader that decrypts embedded resources with 3DES-CBC, decompresses them with GZip, and reflectively executes the resulting assembly. It has been observed carrying additional encrypted inner payloads and delivering malware such as PureLogs, Agent Tesla, RedLine, and other RATs and stealers.
Observed delivery chains place PureCrypter behind phishing and multi-stage loader activity. It has appeared in campaigns using malicious archives, Python loaders, Donut shellcode, PowerShell stages, and process injection or hollowing into legitimate Windows processes. In Fluffy Wolf activity targeting Russian organizations in construction, consulting, manufacturing, engineering, retail, e-commerce, and industrial sectors, PowerLoader downloaded and launched PureCrypter, which then deployed final payloads including PureLogs, PureRAT, and Pay2Key. In SERPENTINE#CLOUD activity targeting German-speaking victims with fake DATEV invoice lures, PureCrypter appeared as a .NET loader stage in a chain involving batch stagers, Python loaders, Donut shellcode, and in-memory execution.
PureCrypter has been associated with the developer PureCoder, who also offers PureRAT, BlueLoader, and PureLogs. It has been used by multiple criminal ecosystems and campaigns, including Fluffy Wolf and SERPENTINE#CLOUD, and it has also been observed as a payload distributed through the Amadey ecosystem. Reported behaviors include sending a TLS 1.2-encrypted infection message via Discord webhook and executing Set-MpPreference -ExclusionPath to add Windows Defender scan exclusions. High-confidence sample references in the content include Ykzrh.exe (SHA256: 6ef97cd831f3cd77ee2dcf98b100b31672887ede7c34ed2017039b9ae434ff9d) identified as PureCrypter, as well as Fviwknzr.exe and Erqcke.exe loader variants described as PureCrypter loaders.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
While they still leverage classic droppers like PureCrypter and Rust-based loaders running Donut shellcode, they have added a potent new tool to their arsenal: PowerLoader.
Its tooling also involves crypters such as HeartCrypt, PureCrypter, and those developed by threat actors like “Roda” and “pjoao1578”...
PureCrypter malware has been observed distributing multiple RATs and information stealers. It is a .NET-based executable, obfuscated with SmartAssembly...
29 distinct techniques documented for this family, organized by ATT&CK tactic.
Security researchers have uncovered a series of highly sophisticated Fluffy Wolf phishing attacks targeting Russian organizations across various critical sectors.
Using highly deceptive tactics, the attackers send emails masquerading as legitimate corporate communications regarding outstanding debts, reconciliation statements, or legal claims. To bypass modern email security gateways, the attackers heavily rely on malicious RAR attachments...
During the 2022 Ukraine Electric Power Attack, Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.
The batch stagers are the initial execution layer. 29 .bat files recovered across six evidence directories deduplicate to 13 unique templates in four categories.
wscript.exe //B \\tunnel1\DavWWWRoot\dat.wsh └─> Cross-tunnel redirect to \\tunnel2\DavWWWRoot\dat.wsf
The ZIP contains a Python runtime and one or more loader scripts. Each loader decrypts embedded shellcode, and that shellcode bootstraps the .NET Common Language Runtime (CLR) to load the actual payload.
During the 2022 Ukraine Electric Power Attack, Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.
The content repeatedly describes malware and threat actors establishing persistence by adding values under HKCU/HKLM\Software\Microsoft\Windows\CurrentVersion\Run or RunOnce, and by placing executables, scripts, .lnk files, or batch files in the Windows Startup folder.
During the 2022 Ukraine Electric Power Attack, Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.
Injection technique: create a suspended notepad.exe , allocate RWX memory, write shellcode via WriteProcessMemory , queue an APC, resume the thread.
Injection technique: create a suspended notepad.exe , allocate RWX memory, write shellcode via WriteProcessMemory , queue an APC, resume the thread... Instead of notepad.exe, the loaders now create a suspended explorer.exe and use Early Bird APC injection
The content repeatedly describes malware and threat actors establishing persistence by adding values under HKCU/HKLM\Software\Microsoft\Windows\CurrentVersion\Run or RunOnce, and by placing executables, scripts, .lnk files, or batch files in the Windows Startup folder.
The content repeatedly describes adversaries using Base64, XOR, RC4, AES, hexadecimal encoding, string encryption, code flattening, custom crypters, and other obfuscation methods to hide payloads, strings, configuration data, URLs, and scripts.
The assembly is heavily protected and contains multiple encrypted resources. Static decompilation shows many stubs, proxy methods, and incomplete code paths.
Obfuscated Files: Encrypted Payload T1027.013 Multi-layer XOR + Chaskey CTR + AES
Masquerading: Match Legitimate Name T1036.005 DATEV invoice filename
Injection technique: create a suspended notepad.exe , allocate RWX memory, write shellcode via WriteProcessMemory , queue an APC, resume the thread.
Injection technique: create a suspended notepad.exe , allocate RWX memory, write shellcode via WriteProcessMemory , queue an APC, resume the thread... Instead of notepad.exe, the loaders now create a suspended explorer.exe and use Early Bird APC injection
The content repeatedly describes adversaries and malware deleting files, directories, droppers, scripts, logs, archives, staged data, and other artifacts from compromised systems, e.g., 'APT29 has used SDelete to remove artifacts from victim networks' and 'Lazarus Group malware has deleted files in various ways, including "suicide scripts" to delete malware binaries from the victim.'
C2 Application Layer Protocol: Web Protocols T1071.001 1–6 WebDAV over HTTPS for staging
Obtaining Embedded Payload Xuvrfuo Decryption... The decompressed payload from Xuvrfuo produced the protected .NET assembly: Uwjoqtb
Defense Evasion Subvert Trust Controls: AMSI Bypass T1562.001 1, 3 Donut AMSI patch + DcRat runtime AMSI patch
The content repeatedly describes threat actors and malware disabling or modifying security tools, EDR/AV, logging, firewall rules, integrity checkers, and security settings; e.g., 'Agrius used several mechanisms to try to disable security tools' and 'BlackByte disabled security tools such as Windows Defender and the Raccine anti-ransomware tool during operations.'
BlackByte Ransomware 'adds .JS and .EXE extensions to the Microsoft Defender exclusion list'; PureCrypter 'executed Set-MpPreference -ExclusionPath'; QakBot 'modify the Registry to add its binaries to the Windows Defender exclusion list'; Raspberry Robin 'add an exception to Microsoft Defender that excludes the entire main drive'; StrongPity 'add directories used by the malware to the Windows Defender exclusions list'; XLoader 'can add the path of its executable to the Microsoft Defender exclusion list'; ZIPLINE 'can add itself to the exclusion list for the Ivanti Connect Secure Integrity Checker Tool.'
37 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
30 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
PureCrypter is mentioned as a payload distributed by a large botnet cluster within the Amadey ecosystem.
Used by Fluffy Wolf as a classic dropper in phishing campaigns to help deliver malicious payloads.
Криптер/загрузчик, который разворачивает финальную полезную нагрузку после запуска PowerLoader.
Protected .NET loader/crypter stage in the chain that reconstructs methods dynamically, decrypts embedded resources, and helps deliver the final PureRAT assembly.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.