Two recruitment-themed malware campaigns use decoy job documents to deliver multi-stage, memory-resident implants after a single click. One campaign distributes a ZIP archive containing a renamed WinWord.exe that DLL-side-loads a malicious component to deploy PureRAT/ResolverRAT; researchers assess its infrastructure and tradecraft as overlapping with the Vietnam-nexus PXA Stealer criminal cluster. The other disguises an LNK shortcut as a PDF, invokes mshta.exe, and retrieves a custom native implant that decrypts and reflectively maps its DLL payload in memory. The second operation has not been attributed to a known threat actor.
Both chains reduce Windows telemetry and analysis visibility through sandbox-evasion measures and Task Scheduler COM-based persistence rather than schtasks.exe, while providing attackers remote-access capability. The PureRAT campaign adds scheduled tasks, WMI event subscriptions, COM hijacking, and mirrored staging directories that can restore removed artifacts. The activity follows prior reporting on job-offer social engineering used to deploy Pure-family malware, including PureHVNC and PureRAT-linked tooling, and shows the continued use of this ecosystem alongside heavily obfuscated loaders and persistence mechanisms.

Pull IOCs and campaign context straight into your stack.
13 events from the most recent confirmed update back to the earliest known activity.
The financially motivated REF1695 operation was active from at least late 2023, distributing trojanized software installers, including ISO images, to compromise Windows hosts for cryptomining and CPA content-locker fraud.
The unattributed native implant performed sandbox checks, assigned victims persistent cryptographic identities, and checked in to a centralized operator platform. It persisted through a COM-registered task disguised as Windows System Update Service and supported reconnaissance, keylogging, screen and microphone capture, payload deployment, and self-removal.
A separate recruitment-themed operation used Job Interview.zip containing a PDF-disguised LNK that launched mshta.exe to retrieve HTA content. The HTA downloaded a fake Lenovo Vantage Service executable and encrypted payload, which were decrypted and manually mapped into memory.
The PureRAT job-offer campaign was assessed with high confidence to overlap a Vietnam-nexus, financially motivated cluster previously associated with PXA Stealer. The assessment cited shared C2 infrastructure, loader artifacts, encoding methods, DLL side-loading, and Apex-themed recruitment branding.
The PureRAT campaign registered four COM-based scheduled tasks, created the FontCacheWorker permanent WMI subscription, and hijacked the MMDeviceEnumerator CLSID to load AudioSes.dll. Its mirrored staging directories could restore deleted artifacts, while in-memory patches targeted AMSI and ETW visibility functions.
A recruitment-themed campaign used Apex Job Description.zip to expose a renamed WinWord.exe, which DLL-side-loaded a malicious AppVIsvSubsystems64.dll. The chain ran a concealed Python loader, displayed a decoy job document, and loaded PureRAT/ResolverRAT entirely in memory.
On the eighth day of the ClickFix intrusion, the actor delivered a Sliver implant that communicated with a Fastly-hosted C2 URL. Sliver executed a PowerShell credential-theft script that prompted for the victim's password and saved it to a ProgramData text file.
On the second day of the intrusion, the actor deployed a newer PureHVNC payload with campaign ID amazon3, packed with Inno Setup and a Rust DLL loader. The loader executed through regsvr32, used anti-analysis checks and an AMSI bypass, and persisted through a scheduled task disguised as Google Updater.
A ClickFix campaign used fake job offers to trick victims into executing a clipboard-copied PowerShell command. The command launched malicious JavaScript that established Startup-folder LNK persistence and delivered PureHVNC configured with campaign ID 2a.
Another REF1695 campaign deployed PureRAT, PureMiner, and a custom XMRig loader while disabling sleep and hibernation to extend mining time. A Umnr_ variant deployed SilentCryptoMiner, whose watchdog restored removed loader and persistence artifacts and injected mining components into explorer.exe.
A PureRAT C2 task instructed infected hosts to download the custom XMRig loader MnrsInstllr_240126.exe from GitHub raw content. The loader retrieved encrypted mining configuration, deployed a renamed XMRig binary and WinRing0x64.sys, and terminated mining when analysis tools were detected.
A separate REF1695 campaign delivered PureRAT v3.0.1 through multistage loaders, dropped a malicious svchost.exe payload, and created the high-privilege ONLOGON task SVCConfig. The PureRAT configuration used multiple C2 domains and the Aesthetics135 mutex and communications key.
A REF1695 campaign used a ReadMe.txt lure to persuade victims to bypass SmartScreen, added Microsoft Defender exclusions, and installed the previously undocumented CNB Bot implant. CNB Bot persisted as a high-privilege scheduled task and supported signed C2 tasking, downloads, updates, and removal.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 81 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
5 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcecyderes.com
Open sourceelastic.co
Open sourceresearch.checkpoint.com
Open sourcenetresec.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.