Netskope Threat Labs

PureCrypter

ATP Sandbox Adv. HeuristicsAV

PureCrypter is a fully featured malware loader developed by a threat actor called PureCoder and in use since at least 2021 to distribute a variety of remote access trojans and information stealers.

First seen
October 2022
Last seen
October 2026
Purecrypter

26 techniques across 6 tactics.

TA0002 Execution

TA0003 Persistence

  • T1547Boot or Logon Autostart Execution

TA0005 Stealth

TA0007 Discovery

  • T1033System Owner/User Discovery
  • T1057Process Discovery
  • T1082System Information Discovery
  • T1518Software Discovery
  • T1614System Location Discovery
  • T1673Virtual Machine Discovery

TA0011 Command and Control

TA0112 Defense Impairment

  • T1685Disable or Modify Tools
Alert Name
ByteCode-MSIL.Trojan.Purecrypter
ByteCode-MSIL.Trojan.PureCrypter
Email-MIME.Trojan.PureCrypter
Gen:Variant.PureCrypter.3
Win32.Exploit.PureCrypter
Win32.Ransomware.PureCrypter
Win32.Trojan.PureCrypter