PureCrypter

MITRE ATT&CK: S9019 View on attack.mitre.org

Aliases: PureCrypter

First seen
2021-01-01 00:00:00
Malware type
loader
Family
Malware family
Operating systems
windows
Related IoCs
35 (35 malicious)
Last IoC activity
2026-09-01 13:12:12
Profile updated
2026-07-07 14:41:58

Context

PureCrypter is a fully-featured malware loader, developed by a threat actor called “PureCoder," that has been in use since at least 2021 to distribute a variety of remote access trojans and information stealers.

Recent IoC activity

36 malicious indicators in Maltiverse are attributed to PureCrypter (S9019). The 20 most recently updated:

TypeIndicatorUpdatedSources
file sample 53f323ed87f66f077eeefee5cba276ecd8b039c64006cb2d16a92f6522aea23c 2026-09-02 2
file sample Installer.iso 2026-09-01 2
file sample 377791b4485710222ac502b3a2c4f247f1d4a9f4b697455f1be51b8f07f50eb4 2026-08-31 2
file sample ZA2A_DONE.ps1 2026-08-29 2
file sample 589c6e11714a0e5474db216062806ad191cdaa9b9b9c4c46bc236cb35a6a5065 2026-08-28 3
file sample Installer_v5021_x64.exe 2026-08-28 1
file sample 3ae49a5b78ab66f58f2d5805940b0f73b46b942dc0ee12bb60bf6ec88425550a 2026-08-24 2
file sample 3603a87718eaa9af9c179be1f867df806673d4199163d430013c5166662a94cf 2026-08-22 2
file sample Ycyfafmudke.exe 2026-08-18 1
file sample TR-31Payment091-H462-J828-N3091-B5740-UHA910-786F-CN87402-M8198.exe 2026-08-15 2
file sample 93ee667d08153cc820c6f46b6f2dc4cf.exe 2026-08-15 1
file sample 1a2400fbdbda33c1c59f47b12deb6a8e.exe 2026-08-11 2
file sample 54ae31830a206a51ba2f122ee92cc81a0bc9663557326e3a5c2b14adbbd7dabc.zip 2026-08-10 1
file sample Exploit Locator.exe 2026-08-10 1
file sample Oauujj.exe 2026-08-09 1
file sample 9936dcddd1348320af7fa9c5446666d22888a28dc3788a532c60afb718cb75cb 2026-08-09 1
file sample VNC-Server-7.14.0-Windows.exe 2026-08-06 3
file sample Uuxcibejso.exe 2026-08-05 2
file sample Rsunmug.exe 2026-08-05 2
file sample Installer_v530_x64_.exe 2026-08-04 1

Detection coverage

  • 2 YARA rules
  • 627 Sigma rules

Malware & tools used

  • Process Discovery (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Mutual Exclusion (attack-pattern)
  • Virtual Machine Discovery (attack-pattern)
  • Web Service (attack-pattern)
  • Disable or Modify Tools (attack-pattern)
  • System Owner/User Discovery (attack-pattern)
  • Match Legitimate Resource Name or Location (attack-pattern)
  • Deobfuscate/Decode Files or Information (attack-pattern)
  • System Location Discovery (attack-pattern)
  • Security Software Discovery (attack-pattern)
  • Debugger Evasion (attack-pattern)
  • Scheduled Task (attack-pattern)
  • Asymmetric Cryptography (attack-pattern)
  • Registry Run Keys / Startup Folder (attack-pattern)
  • Execution Guardrails (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • PowerShell (attack-pattern)
  • Symmetric Cryptography (attack-pattern)
  • Masquerade File Type (attack-pattern)
  • Process Injection (attack-pattern)
  • Hidden Window (attack-pattern)
  • File Deletion (attack-pattern)
  • Delay Execution (attack-pattern)
  • Junk Code Insertion (attack-pattern)

Used by threat actors

Detection rules

  • RUSSIANPANDA_Purecrypter_Core (yara-rule)
  • RUSSIANPANDA_Purecrypter (yara-rule)

Reports & references

  • zscaler.com — Technical Analysis Purecrypter (report)
  • blog.netlab.360.com — Purecrypter Is Busy Pumping Out Various Malicious Malware Families (report)
  • recordedfuture.com — Tag 144S Persistent Grip On South American Organizations (report)
  • prodaft.com — Rig Tlp Clear 1 (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Purecrypter (report)
  • any.run — Pure Malware Family Analysis (report)
  • blog.sekoia.io — Mallox Ransomware Affiliate Leverages Purecrypter In Microsoft Sql Exploitation Campaigns (report)
  • MITRE ATT&CK — S9019 (report)

External references