PureRAT is a .NET-based remote access trojan used in multi-stage intrusion chains to establish persistent interactive access on compromised Windows systems. It has been observed as a final payload delivered through several loader ecosystems, including DLL sideloading chains, Donut-based in-memory execution, PowerShell-driven staging, and fileless delivery mechanisms that conceal payloads inside PNG images. Reported infection vectors include phishing and spearphishing campaigns, malicious shortcut files, ClickFix social engineering, and archive-delivered loaders, with notable targeting of hospitality organizations, hotel staff, and Russian organizations across sectors such as education, government, energy, finance, consulting, manufacturing, retail, and e-commerce.
PureRAT emphasizes stealth and modularity. Observed tradecraft includes reflective .NET assembly loading, process hollowing into legitimate Windows processes, anti-virtualization checks, UAC bypass via trusted Windows utilities, persistence through scheduled tasks, registry Run entries, and Startup-folder shortcuts, and in some cases authenticated WebSocket-based command-and-control. Its operators use it both as a standalone RAT and as part of broader malware-as-a-service ecosystems associated with tools such as PureLogs, BlueLoader, PureCrypter, DonutLoader, and PowerLoader. The malware has been linked to campaigns attributed or associated with actors including Fluffy Wolf, and it has also appeared in broader criminal delivery infrastructures supporting multiple commodity malware families.
Observed PureRAT functionality includes host fingerprinting and reconnaissance, command execution, downloading additional payloads, keylogging, screenshot capture, active-window monitoring, browser and wallet data theft, and remote desktop capability through plugins such as PluginRemoteDesktop. Reporting also notes browser credential and session-related collection in some campaigns, as well as targeting of cryptocurrency wallet applications and browser wallet extensions. In hospitality-focused operations, PureRAT has been used to compromise hotel administrator environments and facilitate theft of booking-platform credentials for downstream fraud. Its repeated use of fileless execution, trusted-process abuse, steganographic payload concealment, and modular plugins makes it a flexible post-compromise access tool for financially motivated intrusion activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
These scripts systematically deploy the final payloads, which include the notorious Pay2Key ransomware, the PureLogs information stealer, and the PureRAT trojan.
However, instead of the promised software, a series of loaders installs a malicious toolkit including CNB Bot, PureRAT, and SilentCryptoMiner.
Credential Theft and Remote Access Surge as AllaKore, PureRAT, and Hijack Loader Proliferate
37 distinct techniques documented for this family, organized by ATT&CK tactic.
Le runtime Node.js ... L’implant JavaScript est exécuté avec un domaine C2 en argument de ligne de commande
That shellcode created signed host processes such as MegArray.exe or Crisp.exe in a suspended state, unmapped their original image, wrote the payload into the process, updated thread context, and resumed execution.
shellcode3.bin ↓ VirtualAlloc / RtlMoveMemory / CreateThread ↓ .NET Loader Stage
The assembly is heavily protected and contains multiple encrypted resources. Static decompilation shows many stubs, proxy methods, and incomplete code paths.
The mapped profiler16.dll stage then read loader-pool.db, a PNG file whose encrypted modules were stored across IDAT chunks.
This decoded its configuration, resolved APIs by hash, and manually mapped profiler16.dll.
The file shown to the user looked like a PDF report, but Rapid7 says it was a right-to-left override (RTLO) masqueraded .scr executable.
and ran it inside an EV-signed Qihoo 360 process through process hollowing
The Fcqleh loader decrypted the embedded payload using AES and GZip.
the script invoked a search-ms: URI that opened the operator’s remote WebDAV share as a Windows Explorer search view filtered to .scr files
In several sandbox-style environments, the installer may only stage persistence. The later Python → shellcode → .NET chain may require reboot, logon, or manual triggering of the persisted Run key.
Once running, the stealer targeted cryptocurrency assets, browser data, messaging sessions, and local application data.
The stealer targeted browser credentials, cookies, session tokens, cryptocurrency wallets and wallet extensions, Telegram tdata , Foxmail data, and a screenshot of the desktop.
224 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
51 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A .NET-based remote access trojan used in the second payload chain, supporting keylogging, screenshots, window monitoring, browser and wallet-extension targeting, Chrome data access, persistence, process hollowing preparation, and C2 communication.
A modular .NET remote access trojan delivered in the DlrtyGames chain, using DLL sideloading, IDAT-carried payload loading, process hollowing, and persistence. The described plugins include keylogging, screenshots, window monitoring, browser/wallet data theft, and C2 communication.
Named by the content as a malware/tool associated with the described intrusion campaign targeting hospitality organizations.
A remote access malware family referenced here as being delivered in ClickFix campaigns to steal Booking.com credentials from hotel staff.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.