From infostealer to full RAT: dissecting the PureRAT attack chain
ID: 3076a40b-1f5e-53b4-a1c5-06909fb0c7dd
STIX ID: report--3076a40b-1f5e-53b4-a1c5-06909fb0c7dd
Feed Name: Bleeping Computer
This Huntress Labs report dissects a layered phishing-to-RAT campaign that chained multiple in-memory Python loaders, a .NET process-hollowing loader, and reflective DLL loading to deliver PureRAT; it documents defensive evasion (AMSI/ETW bypass), credential and browser data theft via a Python stealer exfiltrated over Telegram, full RAT configuration (C2 IP 157.66.26.209, ports 56001–56003, TLS pinning), and provides IOCs, MITRE ATT&CK mapping, and attribution links to the PXA/PureCoder ecosystem.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
