PureRAT Escalates Cyber Threat with Modular Infostealer Tactics

09 Oct 2025

Huntress Labs has uncovered a sophisticated cyber threat, PureRAT, which evolves from a Python-based infostealer to a fully capable remote access trojan. This threat targets users with a chain of payloads that leverage phishing and process hollowing to gain control of the host system.

In-depth threat analysis

The attack begins with a phishing email concealing a malicious ZIP file, which contains a compromised PDF reader and a version.dll executable used for DLL hijacking. The decoded components, including a renamed Python interpreter called svchost.exe, are stored under C:\Users\Public\Windows.

Further phases employ Python scripts employing Base64 and Base85 encoding, escalating through hybrid cryptography with RSA, AES, RC4, and XOR. Persistence is maintained using a Run key labeled "Windows Update Service".

The infostealer phase targets browser credentials and exfiltrates data through the Telegram Bot API.

Key facts

  • Huntress Labs discovered PureRAT chaining ten payloads in 2025.
  • The attack starts with a Python infostealer exploiting phishing techniques.
  • PureRAT uses .NET assembly for process hollowing and fileless execution.
  • The command and control utilizes IP 157.66.26.209 with ports 56001–56003.
  • The threat is linked to the PXA Stealer family and uses the Telegram handle @LoneNone.

Impact / What’s next

PureRAT leverages commercially available malware, increasing its operational capabilities. It advanced from using interpreted scripts to filingless, memory-resident codes, escalating threat levels significantly.

According to Huntress Labs, detecting this threat requires layered defenses against cryptographic techniques, abuse of system tools like certutil, and tampering with AMSI and ETW. With indications linking the threat to Vietnam, infrastructure suggests a shared use of malware components by actors like "PureCoder".

Security teams should be vigilant of PureRAT's sophisticated tradecraft involving dynamic loading of operator-specified plugins like HVNC and keylogging.

Top charts for Desktop Windows

uTorrent

uTorrent

Latest update uTorrent download for free for Windows PC or Android mobile

5
1032 reviews
6398958
downloads
Zona

Zona

Latest update Zona download for free for Windows PC or Android mobile

4
614 reviews
1276527
downloads
WinRAR

WinRAR

Latest update WinRAR download for free for Windows PC or Android mobile

5
735 reviews
496006
downloads
Minecraft

Minecraft

Latest update Minecraft download for free for Windows PC or Android mobile

5
750 reviews
453733
downloads

News and reviews for Desktop Windows

Battlestar Galactica Deadlock Delisting on 2025-11-15

Battlestar Galactica Deadlock, a strategy game by Black Lab Games, faces delisting on all platforms starting 2025-11-15. Existing players remain unaffected.

Read more

Windows 11 Update May Streamline Context Menu

Microsoft revealed a new 'Split ContextMenu' feature for WinUI 3 apps, hinting at potential context menu improvements in Windows 11.

Read more

Tavern Keeper Offers Rich Early Access Experience in Fantasy Setting

Tavern Keeper, by Greenheart Games, impresses with engaging gameplay. Available in early access. Explore diverse realms and unique storytelling.

Read more

Netflix Acquires Rights for Overcooked TV Show

Netflix and A24 to transform Overcooked into a reality show; core team executive produce.

Read more

Tavern Keeper Achieves 'Overwhelmingly Positive' on Steam

Tavern Keeper, a pub sim by Greenheart Games, launched on 2023-11-03 and quickly earned overwhelming positive feedback. The result follows 11 years of development.

Read more

Arc Raiders Update: Key Quest Mechanics Explained

Explore Arc Raiders' What We Left Behind quest. Navigate Buried City, Spaceport, and Dam Battlegrounds for rewards and new quests.

Read more

Epic Store Offers Free Games This Week

Epic Store makes Felix The Reaper and Idle Champions available free from 2025-11-06.

Read more

Epic Games Offers Free Titles 'Felix the Reaper' and 'Idle Champions'

Epic Games releases two free games on 2025-11-06. Players can keep Felix the Reaper and Idle Champions perpetually after claiming them this week.

Read more

EU5 Console Commands Enhance Gameplay Flexibility

Discover how EU5 console commands offer flexibility for players. Useful cheats and Debug Mode improve gameplay experience.

Read more

Shroud Backs Arc Raiders for Game of the Year

Top streamer Shroud rallies support for Arc Raiders to win Game of the Year over Expedition 33 at The Game Awards.

Read more