Description
PureCrypter is a fully featured malware loader developed by a threat actor called PureCoder and in use since at least 2021 to distribute a variety of remote access trojans and information stealers.
Stats
- First seen
- October 2022
- Last seen
- October 2026
Also known as
Purecrypter
MITRE ATT&CK techniques
26 techniques across 6 tactics.
TA0002 Execution
TA0005 Stealth
- T1027Obfuscated Files or Information
- T1036Masquerading
- T1055Process Injection
- T1070Indicator Removal
- T1070.004File Deletion
- T1140Deobfuscate/Decode Files or Information
- T1480Execution Guardrails
- T1480.002Mutual Exclusion
- T1480Execution Guardrails
- T1480.002Mutual Exclusion
- T1564Hide Artifacts
- T1564.003Hidden Window
- T1622Debugger Evasion
- T1678Delay Execution
TA0007 Discovery
TA0011 Command and Control
TA0112 Defense Impairment
- T1685Disable or Modify Tools
Associated groups
Alert name variants
| Alert Name |
|---|
| ByteCode-MSIL.Trojan.Purecrypter |
| ByteCode-MSIL.Trojan.PureCrypter |
| Email-MIME.Trojan.PureCrypter |
| Gen:Variant.PureCrypter.3 |
| Win32.Exploit.PureCrypter |
| Win32.Ransomware.PureCrypter |
| Win32.Trojan.PureCrypter |

