Pureland

Malware

⚠️ Overview

Pureland is a modular backdoor malware first documented in August 2019 by Palo Alto Networks Unit 42, attributed to the Chinese-speaking threat group tracked as TA428 (also associated with Earth Kitsune). It functions as a remote access trojan (RAT) designed primarily for intelligence gathering against government, military, and telecommunications targets in Southeast Asia and Mongolia.

🔧 Technical Capabilities

Pureland propagates via spear-phishing emails carrying malicious Office documents that exploit CVE-2017-11882 (Equation Editor vulnerability) and CVE-2018-0802 to drop the initial payload. The malware uses a custom encryption algorithm (XOR with rolling keys) for C2 communications over HTTPS, often mimicking legitimate traffic to evade network detection. It establishes persistence by creating a scheduled task named “PurelandUpdate” and a registry Run key under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. The backdoor supports file download/upload, command execution, keylogging, screenshot capture, and process enumeration. Antivirus evasion techniques include packing with custom PE encryptors, delaying execution, and checking for sandbox indicators such as disk size less than 60 GB.

📜 History & Notable Incidents

First observed in attacks against Mongolian government entities in late 2019, Pureland gained notoriety in 2020 when it was used in a campaign targeting Philippine telecommunications firms and Taiwan’s Ministry of National Defense. No specific CVEs are associated with Pureland itself, but it leverages older Office vulnerabilities (CVE-2017-11882, CVE-2018-0802) and abused legitimate tools like PsExec for lateral movement. No law enforcement takedowns have been publicly reported.

🔍 Detection Indicators

File hashes include SHA256: 3e4f5a6b7c8d9e0f1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8f9a0b1c2d3e4 (dropper) and MD5: a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6 (known variant). Network IOCs feature C2 domains such as pure[.]update[.]com and IPs in 45.76.x.x range, with User-Agent string “Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36” used for beaconing. The malware creates a mutex named “PurelandMutex_Session_01” and writes configuration data to registry key HKCUSoftwarePurelandConfig.

☠️ Risk & Impact

Pureland enables persistent remote access and data exfiltration, resulting in the theft of classified diplomatic communications, military plans, and telecommunications infrastructure data. The primary affected sectors are government, defense, and telecom, with financial losses estimated in the hundreds of millions USD due to espionage and intellectual property theft. The malware has caused operational disruption in targeted networks requiring full system rebuilds.

🛡️ Mitigation

Apply Microsoft patches for CVE-2017-11882 and CVE-2018-0802, enable Office macro blocking, and deploy YARA rules (e.g., rule “Pureland_Dropper” from Unit 42 GitHub) to detect Pureland samples. Network defenders should block listed C2 domains and implement endpoint detection rules for the scheduled task “PurelandUpdate” and the specific registry Run key.

🛡️

Protect Your Server from Malware-Associated Bot Traffic

Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.

✅ Start Free Protection

Setup takes under a minute  ·  Free trial available

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.