PureRAT is a commercially distributed, .NET-based remote access trojan for Windows developed by PureCoder. Earlier names applied to PureRAT samples include PureHVNC, Hidden Desktop, and ResolverRAT. It uses a modular, plugin-based architecture to provide interactive remote control, surveillance, information theft, and execution of additional payloads. PureRAT is distinct from PureLogs, an infostealer offered by the same developer.
Its capabilities include hidden VNC and remote desktop access with keyboard and mouse control, webcam viewing, microphone capture, real-time keylogging, screenshots, remote command execution, file and process management, HTTP and SOCKS5 reverse proxying, and code injection. It profiles infected systems and reports operating-system information, usernames, security products, webcam availability, active-window titles, and other host details to its command-and-control server. Collection modules target browser data, cryptocurrency wallets and wallet extensions, messaging applications, and email clients. Observed plugins monitor window titles for banking and financial-service activity, capture corresponding screenshots, and replace cryptocurrency addresses in the clipboard with attacker-controlled addresses.
PureRAT uses encrypted command-and-control communications, including TLS-protected connections and Protobuf-encoded messages. Observed versions also use compression and authenticated encryption. Deployment chains frequently employ protected .NET assemblies, encrypted and compressed payload containers, Donut shellcode, reflective in-memory loading, DLL side-loading, and process injection or hollowing. Associated loaders establish persistence through Startup entries, scheduled tasks, autorun entries, WMI event subscriptions, or COM hijacking; some also impair AMSI and ETW telemetry.
Distribution includes phishing emails with recruitment, invoice, booking, damaged-goods, and refund lures; malicious archives containing executables disguised as documents; fake installers; and ClickFix CAPTCHA pages that persuade victims to execute commands. Campaigns have targeted hospitality personnel, Russian organizations, Japanese- and Korean-language business recipients, Canadian organizations, job seekers, and a US accounting firm. PureRAT has been deployed by the financially motivated REF1695 operation and through GhostCrypt-protected infection chains. REF1695 has used PureRAT to download and execute cryptocurrency-mining payloads.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Campaign 2 uses a multi-stage fake-installer chain to drop PureRAT v3.0.1; its C2 issued a download-and-execute task for an XMR mining payload.
in July 2025, eSentire reported an association between PureRAT, a remote access trojan (RAT) first advertised in January 2023, and GhostCrypt, a crypting service sold by an underground forum member of the same moniker, in an attack that impacted a public US accounting firm in May 2025.
These scripts systematically deploy the final payloads, which include the notorious Pay2Key ransomware, the PureLogs information stealer, and the PureRAT trojan.
Credential Theft and Remote Access Surge as AllaKore, PureRAT, and Hijack Loader Proliferate
36 distinct techniques documented for this family, organized by ATT&CK tactic.
[The script] registers the scheduled task wupd_chk to execute every 30 minutes.
Once executed, get.js copies several campaign components... The JavaScript then launches g.bat... Systems that do not match these checks follow a PowerShell based execution path... [other systems] execute the 64-bit AS branch through w.py.
The loader invokes PowerShell with -WindowStyle Hidden to register Defender exclusions, execute extracted stages, and launch payloads.
The JavaScript then launches g.bat with the arguments general x while suppressing the visible command window.
[The script] registers the scheduled task wupd_chk to execute every 30 minutes.
“Campaign 1 adds a WMI event subscription...”
[The script] registers the scheduled task wupd_chk to execute every 30 minutes.
“Campaign 1 adds a WMI event subscription...”
wupd.dll decrypts a large position independent payload in memory... Its contents are decrypted with TripleDES-CBC and then decompressed with GZip, producing a .NET DLL that obscures operational strings behind a Babel-style resource layer and a dynamically generated Hashtable resolver.
support.ico is an XOR-encrypted payload; hda_config.dat uses a custom keystream cipher.
Stage 2 drops a malicious svchost.exe; SilentCryptoMiner copies itself to Appdata/Local/OptimizeMS/optims.exe to masquerade as legitimate software.
The first-run cleanup deletes executables, DLLs, and the _sys folder.
Campaign 1 uses XOR, base64, bzip2, zlib, and marshal; Campaign 2 decrypts a PE with a custom keystream.
Campaign 1 sleeps 180 seconds; Campaign 2 uses uptime gates and a host-specific randomized delay.
Supporting archive entries and staging content carry hidden and system attributes.
g.bat enumerates running processes and checks for products associated with ESET, Kaspersky, AVG, Avira, and Avast.
PureRAT profiles OS version, privilege level, webcam presence, executable path, and installed security products.
PureRAT enumerates wallet paths; Campaign 2 exposes file_ls().
Campaign 1 sleeps 180 seconds; Campaign 2 uses uptime gates and a host-specific randomized delay.
Campaign 1 uses protobuf over TLS; Campaign 2 uses an HTTPS check-in loop.
The shortcut... uses Windows WebDAV syntax to retrieve a remote get.wsh configuration file... additional components can be retrieved and staged remotely. | The infection chain used a document themed lure to move victims into attacker controlled staging infrastructure... it uses Windows WebDAV syntax to retrieve a remote get.wsh configuration file.
PureRAT configuration is a base64/gzip protobuf message; Campaign 2 uses structured JSON tasking.
370 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
68 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Remote access trojan mentioned as a payload delivered through ClickFix fake CAPTCHA pages in earlier hospitality-branded spoofing campaigns. It is background context rather than a reported payload of the latest campaign.
Mentioned as a payload in earlier hotel-targeting campaigns using fake booking messages and ClickFix instructions. The reference does not describe its capabilities or establish its deployment in the current EtherRAT and TONResolver campaign.
Remote access trojan delivered in earlier Booking.com-spoofing campaigns targeting accommodation businesses. Fake CAPTCHA pages used ClickFix social engineering to persuade recipients to execute scripts that downloaded the malware. The report assesses with moderate confidence that the current EtherRAT and TONResolver activity continues these earlier campaigns, while acknowledging that shared kits could explain the overlap.
Remote access malware delivered through business-complaint phishing targeting organizations with Japanese- and Korean-language messages during July–August 2026. Fake document-sharing and video-viewing pages lure recipients into downloading ZIP archives containing disguised executables and DLLs. PureRAT gathers system and user information, captures screenshots, and steals data from browsers, cryptocurrency wallets, and messaging applications. The content identifies tirakian[.]com as its command-and-control server.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.