#PureRAT
Fake complaint emails drop PureRAT/PureLogs - one loader BYOVDs a Lenovo driver to kill your EDR. https://intel.threadlinqs.com/threat/TL-2026-2652 #ThreatIntel #PureRAT #PureCoder #PureLogs
September 25, 2026 at 12:31 PM
September 25, 2026 at 12:24 PM
PureRAT/PureLogs phish hits Japan/Korea via a wall of loaders and a BYOVD EDR-kill - one stealer behind it all. https://intel.threadlinqs.com/threat/TL-2026-2647 #ThreatIntel #PureRAT #PureLogs #Korean
September 25, 2026 at 5:07 AM
Reverse engineering analysis of PureRAT, a multi-stage RAT that executes via msbuild.exe and communicates with C2 servers at
https://
pure8s.ddnsfree.com and 52.241.248.38.

Uses .NET evasion techniques (DisableNativeImageLoad),…

— from @ipurple (https://x.com/ipurple/status/2102336812282675637)
September 22, 2026 at 10:00 AM
“I Paid Twice” Scam Infects Booking.com Users with PureRAT via ClickFix

Cybersecurity firm Sekoia reports a widespread fraud where criminals compromise hotel systems (Booking.com, Expedia and others) with PureRAT malware, then use stolen reservation data to phish and defraud gues…
#hackernews #news
“I Paid Twice” Scam Infects Booking.com Users with PureRAT via ClickFix
Cybersecurity firm Sekoia reports a widespread fraud where criminals compromise hotel systems (Booking.com, Expedia and others) with PureRAT malware, then use stolen reservation data to phish and defraud guests.
hackread.com
November 8, 2025 at 6:59 PM
Threat Actors Leverage Zoho WorkDrive Folder to Deliver Obfuscated PureRAT Malware
Threat Actors Leverage Zoho WorkDrive Folder to Deliver Obfuscated PureRAT Malware
cybersecuritynews.com
July 21, 2025 at 6:18 PM
A hacked MSI installer is stealing banking logins across Mexico.

Greedy Sponge hackers are pushing a weaponized Chrome proxy zip that drops AllaKore RAT—now upgraded to exfiltrate credentials and act as a SOCKS5 proxy.

💰 Financial fraud is the goal. And it’s working. #CyberSecurity #cybercrime
Credential Theft and Remote Access Surge as AllaKore, PureRAT, and Hijack Loader Proliferate
Modified AllaKore RAT and Ghost Crypt crypter target Mexican entities and global victims for financial fraud.
thehackernews.com
July 23, 2025 at 4:43 PM
How to identify #PureRAT (aka #ResolverRAT):
⛳️ C2 port is often 56001, 56002 or 56003
🔢 Bot sends 04 00 00 00, then TLS handshake
🔑 Client and server run TLS 1.0
🖊️ X.509 cert is self signed
📅 X.509 cert expires 9999-12-31
netresec.com?b=2589522
PureRAT = ResolverRAT = PureHVNC
PureRAT is a Remote Access Trojan, which can be used by an attacker to remotely control someone else's PC. PureRAT provides the following features to an attacker: See the victims user interfaceInt...
netresec.com
August 12, 2025 at 6:20 PM
Cybersecurity researchers at Symantec say PureRAT malware is now being built with the aid of AI.

The reason for the conclusion? Emojis throughout the code, likely from social media posts the AI has ripped content from... 👀

www.infosecurity-magazine.com/news/emojis-...
Emojis in PureRAT’s Code Point to AI-Generated Malware Campaign
Researchers discover that PureRAT’s code now contains emojis – indicating it has been written by AI based-on comments ripped from social media.
www.infosecurity-magazine.com
January 28, 2026 at 12:24 PM
Researchers Expose SVG and PureRAT Phishing Threats Targeting Ukraine and Vietnam thehackernews.com/2025/09/rese...
Researchers Expose SVG and PureRAT Phishing Threats Targeting Ukraine and Vietnam
SVG phishing emails drop CountLoader to deploy Amatera Stealer and PureMiner in Ukrainian government attack.
thehackernews.com
September 27, 2025 at 9:12 PM
-CISA and NIST propose new LEV vuln metric
-Unpatched Foscam bugs
-Go crypto has a security audit
-New SCC cyber industry group
-New ENISA NIS2 handbook
-OffensiveCon 2025 videos
-Malware reports on ELPACO-team ransomware, 3AM ransomware, PureRAT, Hannibal Stealer
May 21, 2025 at 9:25 AM
"Priority One
Insure the safe return of more money
For analysis
All other considerations are secondary
Teammates expendable" #nufc #PureRat #IsakEarth #fuckinstagram
August 19, 2025 at 8:24 PM
zgRAT is a confusing catch-all label: both #PureLogs and #PureRAT commonly trigger "zgRAT" detections. Please don't label malware as #zgRAT.
netresec.com?b=267e877
PureLogs, PureRAT and misleading zgRAT
Please stop classifying malware as zgRAT. That malware label is confusing. As far as I know, there isnt a proper definition of what zgRAT actually is. Some claim that zgRAT is the same malware family ...
netresec.com
July 27, 2026 at 4:18 PM
🛑 New and ongoing “I Paid Twice” scam hits hotels and guests using #PureRAT via ClickFix attack. Attackers breach booking accounts like #Booking.com, then message travelers about fake payment issues to steal bank info.

Read 🔗 hackread.com/i-paid-twice...

#Cybersecurity #Malware #Phishing #ClickFix
“I Paid Twice” Scam Infects Booking.com Users with PureRAT via ClickFix
Follow us on Bluesky, Twitter (X), Mastodon and Facebook at @Hackread
hackread.com
November 7, 2025 at 4:04 PM
AI-Powered Job Scam Delivers PureRAT Malware Through Sophisticated Phishing Campaign

Introduction A new phishing campaign linked to a Vietnamese threat actor is showing how artificial intelligence is reshaping cybercrime at street level. By abusing AI tools to generate polished scripts, detailed…
AI-Powered Job Scam Delivers PureRAT Malware Through Sophisticated Phishing Campaign
Introduction A new phishing campaign linked to a Vietnamese threat actor is showing how artificial intelligence is reshaping cybercrime at street level. By abusing AI tools to generate polished scripts, detailed malware loaders, and convincing social engineering lures, the attacker has managed to distribute PureRAT malware through fake job offers. What makes this operation notable is not just the malware itself, but how AI has lowered the technical barrier, allowing relatively unsophisticated actors to deploy complex attack chains with professional-looking code and documentation.
undercodenews.com
January 28, 2026 at 12:41 PM
PureRAT Strikes: Hackers Use Zoho and Ghost Crypt to Breach US Accounting Firm

An Alarming Example of Malware Innovation and Social Engineering A new and highly coordinated cyberattack has been uncovered by eSentire’s Threat Response Unit (TRU), targeting a U.S.-based certified public accounting…
PureRAT Strikes: Hackers Use Zoho and Ghost Crypt to Breach US Accounting Firm
An Alarming Example of Malware Innovation and Social Engineering A new and highly coordinated cyberattack has been uncovered by eSentire’s Threat Response Unit (TRU), targeting a U.S.-based certified public accounting (CPA) firm. What makes this attack so dangerous is the sophisticated mix of social engineering, stealthy malware techniques, and abuse of legitimate cloud services like Zoho WorkDrive. At the heart of the campaign was a powerful remote access trojan known as PureRAT, hidden behind layers of deception and delivered through a malware obfuscation service called Ghost Crypt.
undercodenews.com
July 21, 2025 at 9:35 PM
In this report, we analysed a widespread, persistent campaign distributing the PureRAT malware via the #ClickFix social engineering tactic and emails impersonating Booking[.]com.

We also detailed the fraud scheme targeting hotel customers.
November 6, 2025 at 10:27 AM
"The proof the notification requires for confirmation that there’s a human behind the keyboard is to copy a string of text and paste it into the Windows terminal. With that, the machine is infected with malware tracked as PureRAT."

So, NEVER do that! Better yet, switch to a Linux OS.
The increasingly common infection method, which many potential targets have yet to learn of, is quick, bypasses most endpoint protections, and works against both macOS and Windows users.
ClickFix may be the biggest security threat your family has never heard of
Relatively new technique can bypass many endpoint protections.
arstechnica.com
November 11, 2025 at 4:27 PM
Ghost Crypt's Process Hypnosis injects PureRAT into csc.exe, then hunts your crypto wallets. https://intel.threadlinqs.com/threat/TL-2026-2008 #ThreatIntel #PureRAT #GhostCrypt #Remcos
August 13, 2026 at 2:33 PM
Update:
The two `zgRAT` IOCs that are less than 6 months old were reported as false positives on ThreatFox. The first one has now been re-classified as PureRAT, while the second one is marked as (Unknown malware)[https://threatfox.abuse.ch/ioc/1750083/]. The reason for the `Unknown` tag is […]
Original post on infosec.exchange
infosec.exchange
July 31, 2026 at 7:45 AM
Update:
The two `zgRAT` IOCs that are less than 6 months old were reported as false positives on ThreatFox. The first one has now been re-classified as PureRAT, while the second one is marked as (Unknown malware)[https://threatfox.abuse.ch/ioc/1750083/]. The reason for the `Unknown` tag is […]
Original post on infosec.exchange
infosec.exchange
July 31, 2026 at 7:45 AM