logo

PureRAT Unmasked: The Stealthy, Multi-Stage “Dynamic Loader” Targeting Windows

ID: 8d56e32e-746c-514f-933f-fd5340c5b0a1

STIX ID: report--8d56e32e-746c-514f-933f-fd5340c5b0a1

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-04-23

Date Updated: 2026-04-23

Author: Ddos

...
...

Trellix ARC's analysis describes PureRAT as a sophisticated, modular remote access trojan that uses a deceptive LNK to run concealed PowerShell which fetches an obfuscated VBS loader; the malware hides malicious PE files inside PNG images via steganography for fileless in-memory execution, employs UAC bypass (cmstp.exe), process hollowing (msbuild.exe), anti-VM checks, and implements modules for credential harvesting, audio/video monitoring and remote desktop, with persistence and a C2 at instantservices1.ddnsguru.com.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.