PureCrypter
MITRE ATT&CK: S9019 View on attack.mitre.org
Aliases: PureCrypter
- First seen
- 2021-01-01 00:00:00
- Malware type
- loader
- Family
- Malware family
- Operating systems
- windows
- Related IoCs
- 35 (35 malicious)
- Last IoC activity
- 2026-09-01 13:12:12
- Profile updated
- 2026-07-07 14:41:58
Context
PureCrypter is a fully-featured malware loader, developed by a threat actor called “PureCoder," that has been in use since at least 2021 to distribute a variety of remote access trojans and information stealers.
Recent IoC activity
36 malicious indicators in Maltiverse are attributed to PureCrypter (S9019). The 20 most recently updated:
Detection coverage
- 2 YARA rules
- 627 Sigma rules
Malware & tools used
- Process Discovery (attack-pattern)
- System Information Discovery (attack-pattern)
- Mutual Exclusion (attack-pattern)
- Virtual Machine Discovery (attack-pattern)
- Web Service (attack-pattern)
- Disable or Modify Tools (attack-pattern)
- System Owner/User Discovery (attack-pattern)
- Match Legitimate Resource Name or Location (attack-pattern)
- Deobfuscate/Decode Files or Information (attack-pattern)
- System Location Discovery (attack-pattern)
- Security Software Discovery (attack-pattern)
- Debugger Evasion (attack-pattern)
- Scheduled Task (attack-pattern)
- Asymmetric Cryptography (attack-pattern)
- Registry Run Keys / Startup Folder (attack-pattern)
- Execution Guardrails (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- PowerShell (attack-pattern)
- Symmetric Cryptography (attack-pattern)
- Masquerade File Type (attack-pattern)
- Process Injection (attack-pattern)
- Hidden Window (attack-pattern)
- File Deletion (attack-pattern)
- Delay Execution (attack-pattern)
- Junk Code Insertion (attack-pattern)
Used by threat actors
- APT-C-36 (threat-actor)
Detection rules
- RUSSIANPANDA_Purecrypter_Core (yara-rule)
- RUSSIANPANDA_Purecrypter (yara-rule)
Reports & references
- zscaler.com — Technical Analysis Purecrypter (report)
- blog.netlab.360.com — Purecrypter Is Busy Pumping Out Various Malicious Malware Families (report)
- recordedfuture.com — Tag 144S Persistent Grip On South American Organizations (report)
- prodaft.com — Rig Tlp Clear 1 (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Purecrypter (report)
- any.run — Pure Malware Family Analysis (report)
- blog.sekoia.io — Mallox Ransomware Affiliate Leverages Purecrypter In Microsoft Sql Exploitation Campaigns (report)
- MITRE ATT&CK — S9019 (report)