PureMiner is a Windows-focused .NET cryptominer associated with the PureCoder malware ecosystem and used in financially motivated intrusion chains to monetize compromised hosts through illicit cryptocurrency mining. It has been observed as a final payload delivered by upstream loaders and crypters including PureCrypter and CountLoader, and in broader fake-installer and phishing operations linked to activity clusters such as REF1695. Campaigns distributing PureMiner have used ISO-based lures, SVG attachment phishing, and script-based loader chains involving PowerShell or VBS. PureMiner has also appeared alongside other PureCoder malware such as PureRAT, PureLogs, PureClipper, and BlueLoader, as well as commodity stealers and custom XMRig loaders.
Operationally, PureMiner is described as a stealthy miner that can deploy CPU- or GPU-oriented mining components depending on attacker configuration and host profiling. Reported behavior includes collection of host and graphics-adapter information, use of AMD and NVIDIA APIs for GPU capability assessment, memory checks before mining, serialized command-and-control exchanges, and encrypted communications. Some observed samples decrypted an embedded payload and launched it through process hollowing, while others used DLL sideloading as part of the execution chain. Anti-analysis and stealth features include monitoring for analysis or administrative tools, checking active windows or system idleness, and in some campaigns disabling sleep and hibernation to maximize mining uptime. PureMiner has also been reported in multi-payload infections where it coexisted with credential-stealing malware, indicating operators may combine cryptojacking with data theft for additional monetization.
The malware primarily targets Windows systems and is commonly deployed through socially engineered delivery chains masquerading as legitimate software or official documents. Its repeated use across MaaS-style ecosystems and fake-installer campaigns indicates it is a commoditized cryptomining payload rather than a bespoke one-off implant.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
REF1695 also leveraged ISO lures to spread the PureMiner and PureRAT payloads...
PureMiner This is a hidden stealth silent miner; an attacker can use it for bots or spread it, and it will automatically mine ETHW or BTC to TAs wallet.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
TTP MITRE Technique Description Python-Based Infostealer Payload T1059.006 – Command and Scripting Interpreter: Python Core PXA Stealer signature across all known campaigns
Beyond the C2 infrastructure, the threat actor abuses GitHub as a payload delivery CDN, hosting staged binaries across two identified accounts
These attacks leverage an ISO file as the infection vector to deliver a .NET Reactor-protected loader and a text file with explicit instructions to the user to bypass Microsoft Defender SmartScreen protections against running unrecognized applications by clicking on "More info" and "Run anyway."
9 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
18 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A named PureCoder malware family mentioned as part of the broader PureCoder malware set.
A named PureCoder malware family mentioned as part of the broader PureCoder malware set.
Cryptocurrency mining malware delivered via counterfeit installer and ISO lure campaigns.
A cryptocurrency miner delivered through ISO lure-based campaigns associated with REF1695.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.