PureRAT is a .NET-based remote access trojan associated with the PureCoder malware ecosystem. The name ResolverRAT has been used historically as an alternate or outdated label for PureRAT, alongside names such as PureHVNC and Hidden Desktop, and is not considered a distinct, consistently defined family in current usage. PureRAT provides persistent remote access and interactive control over compromised Windows systems, with capabilities reported to include hidden VNC or remote desktop functionality, webcam and microphone surveillance, real-time keylogging, remote command execution, reverse proxying, and code injection. Recent campaigns have also used dual-payload packaging in which a PureRAT-labeled component was delivered together with LummaStealer, giving operators both persistent access and credential theft capability.
Observed delivery chains tied to samples labeled ResolverRAT have included fake browser update lures associated with ClearFake and ClickFix activity, followed by in-memory execution through a Donut loader and heavily obfuscated .NET payloads protected with .NET Reactor. The malware and related loaders have used encrypted communications, certificate pinning, anti-analysis measures, randomized metadata, forged timestamps, and process hollowing or similar injection techniques to hinder detection and analysis. Reporting has linked campaigns using this malware to financially motivated cybercrime activity targeting sectors including healthcare and pharmaceuticals. Because ResolverRAT is widely described as an older name for PureRAT rather than a separate family, PureRAT is the most appropriate canonical display name.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
15 distinct techniques documented for this family, organized by ATT&CK tactic.
Defense Evasion Obfuscated Files: Software Packing T1027.002 .NET Reactor, 119 GUID-named config fields
Defense Evasion Obfuscated Files: Indicator Removal T1027.005 Forged PE timestamp (2052), encrypted config
MITRE ATT&CK Mapping ... Defense Evasion Masquerading: Match Legitimate Name T1036.005 RuntimeBroker.exe , microsoft-telemetry.at
Defense Evasion Process Injection: DLL Injection T1055.001 Donut loader for in-memory .NET assembly
Command and Control Fallback Channels T1008 22 C2 IPs, 8 domains, 10+ port options
Command and Control Application Layer Protocol T1071.001 HTTPS C2 with certificate pinning
Command and Control Non-Standard Port T1571 Ports 56001, 4782, 1337, 7777, 9090
47 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An outdated or alternate label previously applied to PureRAT samples in this reference, not treated here as a separate malware family.
An outdated name previously used to refer to PureRAT samples in this content.
Remote access trojan that opens a persistent backdoor on port 56001, giving operators interactive access to the compromised machine. In this campaign it is delivered alongside LummaStealer and injected via process hollowing.
Primary remote access trojan in the campaign, delivered via a Donut-loaded .NET payload, using encrypted C2 communications, certificate pinning, and multiple fallback IPs and ports.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.