logo

A Vietnamese threat actor's shift from PXA Stealer to PureRAT

ID: 621d906f-32f2-5926-a0b2-121fc3b28383

STIX ID: report--621d906f-32f2-5926-a0b2-121fc3b28383

Feed Name: Huntress Blog

Threat Score
78/100

Date Published: 2025-09-25

Date Updated: 2026-04-28

...
...

This report describes a complex, multi-stage intrusion that started with a phishing ZIP using DLL sideloading and moved through multiple in-memory Python loaders and an information stealer linked to the PXA ecosystem, before delivering a commercial .NET RAT (PureRAT) via process hollowing and reflective DLL loading; the write-up includes MITRE ATT&CK mappings, defense-evasion details (AMSI/ETW bypass, obfuscation, TLS pinning), and IOCs (file hashes, paths, hosting URLs, and a C2 server at 157.66.26.209 with ports 56001–56003) to aid detection and remediation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.