PureRAT is a Windows .NET remote-access trojan sold as part of the PureCoder malware-as-a-service ecosystem. Older names including PureHVNC, Hidden Desktop, and ResolverRAT have been applied to PureRAT, while the label zgRAT is ambiguous and should not be treated as a deterministic family name. PureRAT provides interactive remote control through hidden VNC and remote-desktop functionality, command-shell access, webcam and microphone access, keylogging, HTTP and SOCKS5 reverse proxying, and code injection. It supports reconnaissance and data collection including host and security-product details, active-window monitoring, screenshots, browser data, cryptocurrency-wallet data, and data associated with messaging and email applications. Plugins have enabled clipboard replacement of cryptocurrency wallet addresses and remote desktop control with mouse and keyboard emulation. Observed campaigns have used phishing emails, archive attachments, employment and business-document lures, fraudulent document-sharing pages, WebDAV delivery, ClickFix lures, DLL sideloading of legitimate signed applications, reflective .NET loading, process hollowing or injection, and persistence through startup execution or registry autorun mechanisms. PureRAT has been deployed against Russian organizations and in campaigns targeting victims in Japan, South Korea, Mexico, and other regions.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
in July 2025, eSentire reported an association between PureRAT, a remote access trojan (RAT) first advertised in January 2023, and GhostCrypt, a crypting service sold by an underground forum member of the same moniker, in an attack that impacted a public US accounting firm in May 2025.
These scripts systematically deploy the final payloads, which include the notorious Pay2Key ransomware, the PureLogs information stealer, and the PureRAT trojan.
However, instead of the promised software, a series of loaders installs a malicious toolkit including CNB Bot, PureRAT, and SilentCryptoMiner.
Credential Theft and Remote Access Surge as AllaKore, PureRAT, and Hijack Loader Proliferate
34 distinct techniques documented for this family, organized by ATT&CK tactic.
One common entry vector we’ve observed is email-based job lures. Archive files, with filenames such as Overview_of_Work_Expectations.zip, Candidate_Skills_Assessment_Test.rar, or Authentic_Job_Application_Form.zip, are deliberately crafted to take advantage of the curiosity and sense of urgency among job seekers.
PureRAT is a Remote Access Trojan (RAT) with many built-in features for live interaction with infected hosts, such as: ... Remote command prompt
The batch file, document.bat, uses the document.docx file to extract the contents of the document.pdf file... Following extraction, the batch file invokes the Python interpreter to execute the malicious Python script, facilitating payload deployment.
This method ensures that the Python script can be executed on the target system even if Python is not pre-installed... Following extraction, the batch file invokes the Python interpreter to execute the malicious Python script... The python.exe was renamed as “zvchost.exe” and runs the script using the “-c” parameter
The campaign investigated in this article demonstrates a layered application of tried-and-tested techniques: social‑engineering lures targeting job seekers, obfuscation through deeply nested directory paths, and execution via DLL sideloading.
DLLには処理に無関係なオーバーレイが存在し、ファイルサイズは75MBである。ファイルサイズ制限のあるセキュリティー製品やサンドボックスでの解析回避を意図していると考えられる。
запускает системную утилиту InstallUtil.exe и внедряет в ее процесс расшифрованный модуль... затем передать ей управление.
CHRDを起点として断片化データをシェルコードへ変換し、.NETローダーはPayloadSource.zipをTripleDES-CBCで復号してGZip展開する。
PureRATは仮想通貨ウォレットおよびメッセージングアプリケーションのデータを窃取し、PureLogsはDiscordデータおよびファイル検索結果を送信する。
PureRATは初回通信時にスクリーンショットを送信し、PureLogsダウンローダーも/userinfoでシステム情報とスクリーンショットを送信する。
Плагин постоянно проверяет буфер обмена на наличие текста, похожего на адрес криптокошелька. Обнаружив подходящие данные, он подменяет содержимое буфера обмена
PureRAT is a Remote Access Trojan (RAT) with many built-in features for live interaction with infected hosts, such as: ... Listening to the microphone
Probing the malicious file’s certificate... exhibits characteristics commonly seen in certificates used by PureRAT SSL as part of its secure communication.
PureRAT is a Remote Access Trojan (RAT) with many built-in features for live interaction with infected hosts, such as: ... Reverse proxy (HTTP and SOCKS5)
After the batch file extracts the content of document.pdf (Python environment) using document.docx (7zip.exe), an encoded base64 is downloaded from 196[.]251[.]86[.]145, containing the Python script that serves as a shellcode loader.
353 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
60 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Pureマルウェアファミリーに属する.NET製のリモートアクセス型マルウェア。C2へセキュリティー製品名、Webカメラの有無、ユーザー・OS情報、アイドル時間、アクティブウィンドウ、実行パス、スクリーンショットを送信する。ブラウザー、暗号資産ウォレット、Telegram DesktopおよびFoxmailのデータを窃取する機能を持つ。
Remote access trojan/backdoor delivered via job-themed phishing archives that abuse Foxit PDF Reader DLL sideloading. The chain uses a malicious msimg32.dll, hidden batch/script execution, extraction of a bundled Python environment, download of a base64-encoded Python shellcode loader, persistence via autorun registry entry, and theft of browser data from Chromium-based profiles.
Remote access trojan associated with the GhostCrypt crypting service in an attack against a US accounting firm.
Remote access trojan mentioned as related to one crypting threat actor.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.