PureRAT

Aliases: PureHVNC, ResolverRAT

First seen
2021-06-01 00:00:00
Malware type
rat
Family
Malware family
Last IoC activity
2026-07-22 02:39:17
Profile updated
2026-07-07 14:53:02

Targeted industries: financial-services government-and-public-sector technology-and-telecommunications

Context

According to Morphisec, this RAT combines advanced in-memory execution, API and resource resolution at runtime, and layered evasion techniques. They have named it ‘Resolver’ due to its heavy reliance on runtime resolution mechanisms and dynamic resource handling, which make static and behavioral analysis significantly more difficult.

Reports & references

  • blog.plainbit.co.kr — Sanae Yuib Seupieopising Meil Bunseog (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Pure Rat (report)
  • darkrym.com — Pxa Stealers Evolution To Purerat Part 6 Finally The Final Stage Purerat Stage 9 (report)
  • darkrym.com — Python Malware Part6 (report)
  • morphisec.com — New Malware Variant Identified Resolverrat Enters The Maze (report)
  • netresec.com (report)
  • securelist.ru — 112619 (report)

External references