PureCrypter is a C# malware-as-a-service loader and payload-protection framework active since at least 2021. Marketed by the developer known as PureCoder (also called PureTeam), it is part of a commercial criminal toolset that includes PureRAT, PureLogs, BlueLoader, PureMiner, and PureClipper. PureCrypter is used to deliver unrelated second-stage malware, including information stealers, remote-access trojans, cryptominers, ransomware, and other commodity payloads.
PureCrypter commonly uses a staged downloader-and-injector design: an initial component retrieves a protected injector, which decrypts, unpacks, and executes or injects the final payload. Payload protection has included byte reversal, compression, symmetric encryption, resource-based storage, obfuscation, and benign-looking multimedia or image disguises. The injector supports multiple process-injection techniques, with process hollowing frequently observed. It can also create mutexes, establish Windows persistence, identify installed security products, perform debugger, sandbox, virtualization, display, and username checks, patch or bypass defensive telemetry mechanisms, and attempt to add Microsoft Defender exclusions or elevate privileges.
PureCrypter has been observed in phishing-driven and trojanized or cracked-software infection chains, as well as in compromises of exposed MS-SQL servers. It has been used by multiple criminal operators, including activity associated with the Mallox ransomware ecosystem, APT-C-36, and campaigns targeting Russian and South American organizations. Its modular, configurable design enables affiliates to use it as an evasive execution layer for payloads such as AgentTesla, RedLine, Formbook, SnakeKeylogger, AsyncRAT, Raccoon, Mars Stealer, PureMiner, PureLogs, PureRAT, and Mallox. PureCrypter targets Windows systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The late-2023 PureRAT v0.3.8B build used an in-memory PE loader component protected with SmartAssembly-protected PureCrypter.
APT-C-36 has utilized well known malware including the Packer-as-a-Service HeartCrypt, PureCrypter, and open-source RATs such as Remcos.
The payloads dropped through MS-SQL exploitation correspond to PureCrypter... This third-party payload is the Mallox ransomware.
While they still leverage classic droppers like PureCrypter and Rust-based loaders running Donut shellcode, they have added a potent new tool to their arsenal: PowerLoader.
PureCrypter malware has been observed distributing multiple RATs and information stealers. It is a .NET-based executable, obfuscated with SmartAssembly...
38 distinct techniques documented for this family, organized by ATT&CK tactic.
The module checked the output of WMI queries to identify a virtual or sandbox environment.
запускает системную утилиту InstallUtil.exe и внедряет в ее процесс расшифрованный модуль... затем передать ей управление.
создает в папке Startup VBS-скрипт Task.vbs для автозапуска... копирует StilKrip.exe в папку %AppData% под именем Action.exe и создает в папке Startup VBS-скрипт Action.vbs для автозапуска.
The file byte order is reversed, likely to evade detection by host-based controls. The loader restores the byte order and then performs multiple rounds of extraction and decoding of nested resources to get to the final malicious code.
внутри которого находится исполняемый файл, маскирующийся под PDF-документ... Кроме того, злоумышленники используют двойное расширение .pdf.rar.
запускает системную утилиту InstallUtil.exe и внедряет в ее процесс расшифрованный модуль... затем передать ей управление.
If any of these failed, the sample started a clean-up operation by using PowerShell to delete itself from disk, closing its mutex, and exiting.
запускает системную утилиту InstallUtil.exe и внедряет в ее процесс расшифрованный модуль.
установка различных методов автозапуска и проверка окружения на отладку или виртуальную среду.
Agent Tesla has used ProcessWindowStyle.Hidden to hide windows. APT-C-36 has set the ShowWindow property of the Win32_ProcessStartup object to zero to hide PowerShell execution. APT19 used -W Hidden to conceal PowerShell windows by setting the WindowStyle parameter to hidden.
Скачав файл, StilKrip.exe расшифровывает его и выполняет. При этом все действия он совершает в памяти собственного процесса, и на диске ничего не создается.
установка различных методов автозапуска и проверка окружения на отладку или виртуальную среду.
Adversaries may attempt to get a listing of security software, configurations, defensive tools, and sensors that are installed on a system or in a cloud environment.
156 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
45 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Payload crypter mentioned only as part of a prior Lumma Stealer campaign comparison.
A named component of the PureCoder malware ecosystem; no use in either campaign is described.
PureCrypter is a Malware-as-a-Service loader/crypter used here to download, decrypt, and reflectively load the next-stage Mallox ransomware. It includes anti-analysis checks, ETW and AMSI patching, Defender exclusions, persistence, and privilege adjustment.
TAG-144’s Persistent Grip on South American Organizations AsyncRAT BitRAT DCRat LimeRAT NjRAT PureCrypter Quasar RAT Remcos
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.