PureMiner is a stealth-focused .NET cryptominer marketed within the PureCoder malware suite. It targets Windows systems and can deploy CPU- or GPU-based cryptocurrency-mining modules according to attacker configuration. It profiles host hardware, including video adapters and GPU memory, using AMD and NVIDIA interfaces, and checks available memory before mining. Observed variants encrypt command-and-control traffic, receive serialized tasking, can download and execute additional payloads, and monitor analysis tools, active windows, and system idle state to reduce mining visibility. PureMiner has been distributed through fraudulent software-installer ISO images in financially motivated REF1695 activity and through phishing chains targeting Ukraine that used malicious SVG attachments and follow-on loader stages. It has also been delivered by the PureCrypter loader service. REF1695-associated activity used PureMiner alongside PureRAT and custom XMRig loaders to monetize compromised hosts through cryptomining.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Campaign 3 drops multiple embedded payloads, including PureRAT, a custom XMRig loader, and PureMiner.
PureMiner This is a hidden stealth silent miner; an attacker can use it for bots or spread it, and it will automatically mine ETHW or BTC to TAs wallet.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
The loader invokes PowerShell with -WindowStyle Hidden to register Defender exclusions, execute extracted stages, and launch payloads.
TTP MITRE Technique Description Python-Based Infostealer Payload T1059.006 – Command and Scripting Interpreter: Python Core PXA Stealer signature across all known campaigns
Beyond the C2 infrastructure, the threat actor abuses GitHub as a payload delivery CDN, hosting staged binaries across two identified accounts
These attacks leverage an ISO file as the infection vector to deliver a .NET Reactor-protected loader and a text file with explicit instructions to the user to bypass Microsoft Defender SmartScreen protections against running unrecognized applications by clicking on "More info" and "Run anyway."
9 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A named component of the PureCoder malware ecosystem; no use in either campaign is described.
A named PureCoder malware family mentioned as part of the broader PureCoder malware set.
A named PureCoder malware family mentioned as part of the broader PureCoder malware set.
Cryptocurrency mining malware delivered via counterfeit installer and ISO lure campaigns.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.