logo

From infostealer to full RAT: dissecting the PureRAT attack chain

ID: 3076a40b-1f5e-53b4-a1c5-06909fb0c7dd

STIX ID: report--3076a40b-1f5e-53b4-a1c5-06909fb0c7dd

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2025-10-09

Date Updated: 2026-07-17

Author: Sponsored by Huntress Labs

...
...

This Huntress Labs report dissects a layered phishing-to-RAT campaign that chained multiple in-memory Python loaders, a .NET process-hollowing loader, and reflective DLL loading to deliver PureRAT; it documents defensive evasion (AMSI/ETW bypass), credential and browser data theft via a Python stealer exfiltrated over Telegram, full RAT configuration (C2 IP 157.66.26.209, ports 56001–56003, TLS pinning), and provides IOCs, MITRE ATT&CK mapping, and attribution links to the PXA/PureCoder ecosystem.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.