PureLocker
- Malware type
- ransomware
- Profile updated
- 2026-07-07 15:16:49
Targeted industries: financial-services healthcare-and-pharmaceutical
Context
PureLocker is a sophisticated ransomware that has been known to target primarily the financial services and healthcare industries. It is notable for its use of fileless techniques to avoid detection and operates across multiple platforms.
Detection coverage
- 2 YARA rules
Detection rules
- TRELLIX_ARC_Purelocker_Ransomware (yara-rule)
- MALPEDIA_Win_Purelocker_Auto (yara-rule)
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Win.Purelocker (report)
- intezer.com — Blog Purelocker Ransomware Being Used In Targeted Attacks Against Servers (report)
- github.com — Purelocker.Md (report)
- exchange.xforce.ibmcloud.com — 99C7156Cff70E1D8E1687Ab7Dadc8C0E (report)