logo

Technical Analysis of PureCrypter

ID: 012aa1f4-941b-5785-92b8-2552d0d3e1f7

STIX ID: report--012aa1f4-941b-5785-92b8-2552d0d3e1f7

Feed Name: Zscaler Security Research Blog

Threat Score
75/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

This report analyzes PureCrypter, a SmartAssembly‑obfuscated .NET loader sold since at least March 2021 that downloads and decrypts staged payloads and injects a variety of RATs and stealers (e.g., AgentTesla, RedLine, SnakeKeylogger). The analysis covers its multi-stage downloader and injector, protobuf-driven configuration options (persistence, injection, anti-analysis, Discord/Telegram notifications), resource compression/encryption, multiple injection techniques (process hollowing, shellcode, assembly loading), defensive checks, and provides IoCs and sample hashes used in observed campaigns.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.