PureRAT is a .NET-based remote access trojan sold in the PureCoder malware ecosystem and commonly delivered as part of multi-stage criminal intrusion chains. It has been observed in campaigns targeting Russian organizations, hospitality businesses, and other enterprises, and has also appeared in broader malware-as-a-service operations alongside related tooling such as PureCrypter, PureLogs, BlueLoader, GhostCrypt, DonutLoader, and PowerLoader. Older or inconsistent labels such as PureHVNC, Hidden Desktop, ResolverRAT, and zgRAT have been used for some samples, but PureRAT is the more precise family name.
PureRAT provides interactive control over infected Windows systems. Reported capabilities include Hidden VNC and remote desktop control, webcam and microphone access, real-time keylogging, remote command execution, reverse proxying over HTTP and SOCKS5, code injection, screenshot capture, active-window monitoring, and plugin-based extension of functionality. Observed plugins and modules have supported desktop surveillance, monitoring of banking- and finance-related window titles, clipboard hijacking of cryptocurrency wallet addresses, browser and wallet-extension targeting, and collection of host profiling data for command-and-control. Some campaigns also used PureRAT to execute PowerShell commands for reconnaissance and to retrieve additional payloads.
Delivery has been observed through several mechanisms. Common infection vectors include phishing emails carrying malicious archives or links to archives, often using business-document lures and disguised executables. Hospitality-focused operations used spearphishing and ClickFix-style social engineering to induce victims to run PowerShell-based stages. Other chains used DLL sideloading through legitimate applications, including PDF readers and signed binaries, as well as staged loaders, process hollowing, reflective .NET loading, and in-memory execution to reduce on-disk exposure. PureRAT has also been delivered through binders and multi-stage droppers that inject into legitimate Windows processes.
Persistence and evasion are recurring features in observed deployments. Campaigns have used Startup-folder shortcuts or scripts, Run-key persistence, DLL sideloading, process injection, process hollowing, reflective assembly loading, encrypted and compressed payload stages, and crypter services to hinder detection and analysis. Communications have been described as TLS- or SSL-protected in multiple cases, with some reporting noting evolution from earlier, easier-to-detect implementations to more mature encrypted traffic.
PureRAT has been linked to multiple criminal campaigns rather than a single operator. It has been used by actors targeting Russian organizations, by hospitality-focused credential theft operations abusing booking-platform workflows, and in delivery chains associated with GhostCrypt and other malware-enablement services. The malware is best characterized as a modular Windows RAT used for remote control, surveillance, credential and wallet-related theft, and follow-on payload delivery in financially motivated intrusion activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
in July 2025, eSentire reported an association between PureRAT, a remote access trojan (RAT) first advertised in January 2023, and GhostCrypt, a crypting service sold by an underground forum member of the same moniker, in an attack that impacted a public US accounting firm in May 2025.
These scripts systematically deploy the final payloads, which include the notorious Pay2Key ransomware, the PureLogs information stealer, and the PureRAT trojan.
However, instead of the promised software, a series of loaders installs a malicious toolkit including CNB Bot, PureRAT, and SilentCryptoMiner.
Credential Theft and Remote Access Surge as AllaKore, PureRAT, and Hijack Loader Proliferate
36 distinct techniques documented for this family, organized by ATT&CK tactic.
Основной механизм распространения Pure в рамках этой кампании — спам с вредоносным вложением в виде RAR-архива или ссылкой на архив.
Encrypting and packing EXE/.NET files to make each output look unique and harder to detect
Claims generation of FUD payloads, crypting/packing of x86 Windows PE executables and DLLs
внутри которого находится исполняемый файл, маскирующийся под PDF-документ... Кроме того, злоумышленники используют двойное расширение .pdf.rar.
Le leurre principal ReportFinal.rcs.pdf (exécutable .scr masqué par RTLO)
Le leurre principal ReportFinal.rcs.pdf (exécutable .scr masqué par RTLO)
запускает системную утилиту InstallUtil.exe и внедряет в ее процесс расшифрованный модуль... затем передать ей управление.
Le stealer ciblait : wallets crypto, données navigateur, sessions Telegram ( tdata ), Foxmail
При обнаружении таких окон он делает скриншот... Обнаружив подходящие данные, он подменяет содержимое буфера обмена и делает скриншот.
Плагин постоянно проверяет буфер обмена на наличие текста, похожего на адрес криптокошелька. Обнаружив подходящие данные, он подменяет содержимое буфера обмена
Для общения с командным сервером PureRAT устанавливает SSL-соединения и передает сообщения в формате protobuf, упакованные в gzip.
PureRAT is a Remote Access Trojan (RAT) with many built-in features for live interaction with infected hosts, such as: ... Reverse proxy (HTTP and SOCKS5)
PureRAT is a Remote Access Trojan (RAT) with many built-in features for live interaction with infected hosts, such as: ... Reverse proxy (HTTP and SOCKS5)
В ответ от С2 приходит несколько сообщений, содержащих дополнительные модули (плагины) и конфигурацию к ним... способен выкачивать по переданному URL файл и запускать его.
240 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
58 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Remote access trojan associated with the GhostCrypt crypting service in an attack against a US accounting firm.
Remote access trojan mentioned as related to one crypting threat actor.
A .NET Remote Access Trojan developed by PureCoder that provides extensive remote control capabilities over infected systems, including HVNC, surveillance, keylogging, proxying, command execution, and code injection.
A .NET-based Remote Access Trojan developed by PureCoder that provides extensive remote control capabilities over infected systems, including HVNC, surveillance, keylogging, proxying, command execution, and code injection.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.