Technical Analysis of PureCrypter
ID: 012aa1f4-941b-5785-92b8-2552d0d3e1f7
STIX ID: report--012aa1f4-941b-5785-92b8-2552d0d3e1f7
Feed Name: Zscaler Security Research Blog
This report analyzes PureCrypter, a SmartAssembly‑obfuscated .NET loader sold since at least March 2021 that downloads and decrypts staged payloads and injects a variety of RATs and stealers (e.g., AgentTesla, RedLine, SnakeKeylogger). The analysis covers its multi-stage downloader and injector, protobuf-driven configuration options (persistence, injection, anti-analysis, Discord/Telegram notifications), resource compression/encryption, multiple injection techniques (process hollowing, shellcode, assembly loading), defensive checks, and provides IoCs and sample hashes used in observed campaigns.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
