Security researchers and email threat monitors reported continued activity from the PureCoder malware ecosystem, with campaigns distributing credential-stealing and remote-access payloads including PureLogs, PureRAT, and PureHVNC. An analysis of the broader Pure malware family described it as a growing threat, while Italian malspam telemetry later showed PureHVNC appearing alongside AgentTesla, FormBook, and Remcos in business-themed phishing lures tied to bank transfers, orders, offers, and requests. Script files were the most common attachment type in those campaigns, followed by Office documents and MSIL binaries.
Researchers also warned that industry naming around this malware remains inconsistent, especially the use of zgRAT to describe different PureCoder families. Netresec said the label is being applied to both PureLogs, a .NET infostealer focused on credential and data theft, and PureRAT, a .NET RAT that supports capabilities such as HVNC, webcam and microphone access, keylogging, reverse proxying, and code injection. The report said this overlap affects Suricata and TLS-certificate-based detections, creating false positives and family-level misclassification, and urged defenders to use precise names such as PureLogs or PureRAT when attribution is clear.

Pull IOCs and campaign context straight into your stack.
3 events from the most recent confirmed update back to the earliest known activity.
Netresec published research arguing that the zgRAT label is misleading because it is inconsistently applied to two distinct PureCoder malware families: PureLogs and PureRAT. The post also noted that existing detections using labels such as zgRAT, PureHVNC, and ResolverRAT contribute to false positives and family-level misclassification.
TG Soft's CRAM reported that during the week of 2026-07-20 to 2026-07-26, monitored malspam campaigns in Italy prominently involved password stealers and RATs including PureHVNC, AgentTesla, FormBook, and Remcos. The report counted 70 total campaigns, 12 in Italian targeting Italy, with the highest activity on Monday 2026-07-20.
ANY.RUN published an analysis describing the Pure malware family as a unique and growing threat. The reference indicates this analysis was released on 2024-01-16.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 12 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
4 references tracked. Mallory keeps watching after this page renders.
netresec.com
Open sourcenetresec.com
Open sourcetgsoft.it
Open sourceany.run
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.