PureCoder is the developer identity associated with the commercial malware family PureLogs and a broader ecosystem of commoditized malicious tooling marketed to other threat actors. PureLogs is a .NET information stealer designed to collect browser-stored data, credentials, cookies, history, autofill data, application tokens, and cryptocurrency-wallet data. Reported associated offerings include PureCrypter, a .NET crypter used to protect and deliver payloads; PureMiner, a cryptocurrency miner; PureHVNC, a hidden VNC remote-access tool; and BlueLoader, a botnet framework advertised with persistence, bot management, DDoS, and bot-killing capabilities. This positions PureCoder primarily as a malware developer and seller supporting downstream criminal operations rather than as a single intrusion operator tied to one campaign. PureCoder-linked malware has been used in spam-delivered infections in which victims are lured into opening archived payloads that unpack a loader, decrypt an embedded payload in memory, and execute the final stealer through .NET reflection. PureLogs has been documented stealing credentials and tokens from browsers and applications including messaging, email, gaming, and VPN software, as well as collecting data from numerous cryptocurrency wallets. Observed behaviors associated with PureLogs and related tooling include initial access through user execution, defense evasion through obfuscation and in-memory loading, system and file discovery, automated local data collection, credential theft, crypto-theft, persistence in related tooling, DDoS capability in related tooling, and exfiltration over application-layer protocols. Known aliases directly supported at high confidence are limited to PureCoder.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
9 malware families attributed to this actor across reporting.
4 additional families tracked in Mallory.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Commodity credential/data theft operations associated with development of the PureLogs Stealer, delivered via phishing lures (e.g., fake pharmaceutical invoices) and staged loaders.
Malware developer/vendor selling a suite of .NET cybercrime tools (stealer, crypter/loader, miner, botnet loader, HVNC) via a website and cybercrime forums; their tools are used by other threat actors in campaigns.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.