PureRAT is a .NET-based remote access trojan developed by PureCoder. Older labels including PureHVNC, Hidden Desktop, and ResolverRAT have historically been used for this malware family, but current usage increasingly favors PureRAT to distinguish it from the separate PureLogs infostealer family. PureRAT provides interactive remote-control capabilities centered on hidden desktop or HVNC functionality, and reported features include remote desktop control, webcam viewing, microphone capture, real-time keylogging, remote command execution, reverse proxying over HTTP and SOCKS5, and code injection. Observed campaigns also associate PureRAT/PureHVNC with theft of browser data and cryptocurrency wallet data, collection of basic host information, and checks for attached camera devices.
PureRAT has been delivered in multiple crimeware distribution ecosystems, including malspam and phishing campaigns using business-themed lures, as well as ClickFix-style social engineering chains that rely on user-executed PowerShell and staged payload delivery. Delivery chains observed for PureRAT/PureHVNC include Python-based loaders, shellcode stages, DLL side-loading, InstallUtil abuse, and process injection, reflecting a strong emphasis on stealth and defense evasion. It has also appeared alongside other commodity malware families such as STXRAT, PureLogs, DcRat, AsyncRAT, XWorm, Remcos, and FormBook in multi-stage or parallelized intrusion chains.
Victimology is broad and consistent with financially motivated cybercrime rather than a narrowly targeted espionage tool. PureRAT has been observed in widespread email-borne campaigns targeting business users, including Italian-language malspam operations using invoice, order, request, payment, shipment, and bank-transfer themes. The malware is primarily associated with Windows environments and is commonly deployed as part of malware-as-a-service-style ecosystems that prioritize persistence, covert remote access, credential and data theft, and post-compromise operator control.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
As documented by OpenSourceMalware, the adversary leveraged the network to host a PUREHVNC RAT C2.
20 distinct techniques documented for this family, organized by ATT&CK tactic.
The execute_shellcode function contains a huge base64-encoded string, which is decrypted using RC4, allocated as executable memory using Windows APIs, and then jumped into.
2026-04-10 11:04+ > Repeated PowerShell Invoke-Expression chains (non-interactive); dynamic .NET recompilation; multiple STXRAT beacon renewals
lamoor.vbs is a simple VBScript that downloads and executes a file also called WSJ25F.bat
The startup file changes the directory to %Userprofile%\Downloads\Support\Python312 and executes the Python scripts EAdate.py, FAScis.py, GXrop.py and HPUope.py
When opening the .SVG file in a web browser, the contained JavaScript code is executed, which extracts a .HTM file from a base64 blob and “downloads” it.
The execute_shellcode function contains a huge base64-encoded string, which is decrypted using RC4, allocated as executable memory using Windows APIs, and then jumped into.
WSJ25F.bat is an obfuscated batch script... The startup file changes the directory to %Userprofile%\Downloads\Support\Python312 and executes the Python scripts... Upon opening one of the scripts, we were greeted by this monstrosity: # Pyarmor 9.0.7
The execute_shellcode function contains a huge base64-encoded string, which is decrypted using RC4
The campaign also highlights increasing abuse of legitimate Windows utilities and trusted binaries to evade conventional security controls.
PowerShell: csc.exe compiles ClassLibrary17.dll from %TEMP%; InstallUtil.exe /u launches PureHVNC component; C2: 176.65.144[.]46:65001
171 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
43 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An outdated label previously used for PureRAT samples, especially referencing its hidden VNC capability, rather than a distinct malware family in this article.
An older name used for PureRAT rather than a distinct malware family in this content.
Named as a malware family seen using the same two-ZIP Python runtime plus payload delivery pattern in this ecosystem.
PureHVNC2
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.