PureHVNC is a legacy name for PureRAT, a .NET remote access trojan developed by PureCoder; the PureHVNC and Hidden Desktop labels were used for PureRAT samples until approximately 2023. PureRAT provides Hidden VNC and remote desktop access, remote command execution, webcam viewing, microphone capture, real-time keylogging, HTTP and SOCKS5 reverse proxying, and code injection. Samples identified under the legacy PureHVNC label have also been reported collecting browser data, cryptocurrency-wallet data, and basic host information. PureHVNC/PureRAT has been distributed through business-themed malspam, including Italian-language invoice, order, request, payment, and bank-transfer lures, and through ClickFix-style social engineering that induces victims to execute PowerShell. Observed delivery chains have used staged payloads, DLL side-loading, persistence, and in-memory process injection to reduce visibility. It targets Windows systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
As documented by OpenSourceMalware, the adversary leveraged the network to host a PUREHVNC RAT C2.
21 distinct techniques documented for this family, organized by ATT&CK tactic.
On a rainy Friday around lunchtime, we received a phishing email saying we had an unpaid invoice, with an attached SVG file.
The Italian campaigns ... were grouped according to macro categories, obtained from the subject of the email message used for malware distribution (malspam). The top-ranking samples this week are Script files ... Office documents ... follow in second place.
The execute_shellcode function contains a huge base64-encoded string, which is decrypted using RC4, allocated as executable memory using Windows APIs, and then jumped into.
The initial command uses iex(irm ...), while a later PowerShell process runs with "-NoProfile -NonInteractive -NoLogo -Command -" and receives its script via STDIN.
lamoor.vbs is a simple VBScript that downloads and executes a file also called WSJ25F.bat
The startup file changes the directory to %Userprofile%\Downloads\Support\Python312 and executes the Python scripts EAdate.py, FAScis.py, GXrop.py and HPUope.py
When opening the .SVG file in a web browser, the contained JavaScript code is executed, which extracts a .HTM file from a base64 blob and “downloads” it.
The execute_shellcode function contains a huge base64-encoded string, which is decrypted using RC4, allocated as executable memory using Windows APIs, and then jumped into.
It assembles the cmdlet name at runtime as 'Invoke-We' + 'bRequest'... The interpreter name pythonw.exe is built up a character at a time.
The hidden pythonw.exe RC4-decrypts an encrypted stage, j7gTcSQdBc15W11UfhQkrIw3WG.jsxi, with a hardcoded key and runs it entirely in memory through exec().
The decrypted stage... injects into a freshly spawned winver.exe... the winver.exe injection is the same move to hollow a small signed binary.
The execute_shellcode function contains a huge base64-encoded string, which is decrypted using RC4
The campaign also highlights increasing abuse of legitimate Windows utilities and trusted binaries to evade conventional security controls.
171 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
45 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A password-stealer family observed in malspam campaigns targeting Italy during the reporting week.
An outdated label previously used for PureRAT samples, especially referencing its hidden VNC capability, rather than a distinct malware family in this article.
An older name used for PureRAT rather than a distinct malware family in this content.
Named as a malware family seen using the same two-ZIP Python runtime plus payload delivery pattern in this ecosystem.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.