A Vietnamese threat actor's shift from PXA Stealer to PureRAT
ID: 621d906f-32f2-5926-a0b2-121fc3b28383
STIX ID: report--621d906f-32f2-5926-a0b2-121fc3b28383
Feed Name: Huntress Blog
This report describes a complex, multi-stage intrusion that started with a phishing ZIP using DLL sideloading and moved through multiple in-memory Python loaders and an information stealer linked to the PXA ecosystem, before delivering a commercial .NET RAT (PureRAT) via process hollowing and reflective DLL loading; the write-up includes MITRE ATT&CK mappings, defense-evasion details (AMSI/ETW bypass, obfuscation, TLS pinning), and IOCs (file hashes, paths, hosting URLs, and a C2 server at 157.66.26.209 with ports 56001–56003) to aid detection and remediation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
