PureLocker
Malware⚠️ Overview
PureLocker is a ransomware family first discovered in June 2019 by Morphisec researchers, written in the PureBasic programming language, and operated by a financially motivated threat group that has been linked to TA505 and other cybercriminal clusters. It primarily targets enterprise networks in healthcare, finance, and education sectors, using custom encryption algorithms to extort victims for Bitcoin payments.
🔧 Technical Capabilities
PureLocker employs multiple attack vectors including phishing emails with malicious attachments, exploited remote desktop protocol (RDP) connections, and supply-chain compromises to gain initial access. Once inside a network, it uses process hollowing and dynamic API resolution to evade static detection, and leverages living-off-the-land binaries (LOLBins) such as PowerShell and WMIC for lateral movement. The ransomware encrypts files using a hybrid scheme of AES-256 (per-file key) and RSA-2048 (to protect the AES keys), appending the extension .pure to encrypted files. Command-and-control (C2) communication is conducted over HTTPS to api.purelocker[.]xyz and similar domains, with traffic mimicking legitimate HTTPS requests to bypass network monitoring. Persistence is achieved through scheduled tasks or Windows service creation, and the malware includes anti-debugging and anti-VM checks using the IsDebuggerPresent and CheckRemoteDebuggerPresent API calls.
📜 History & Notable Incidents
PureLocker first appeared in June 2019 when Morphisec detected a campaign targeting healthcare organizations in the United States and Israel, with ransom demands ranging from $10,000 to $50,000 in Bitcoin. In early 2020, a second wave compromised several financial institutions in Europe, exploiting the CVE-2019-19781 vulnerability in Citrix ADC appliances to gain initial access. No law enforcement takedowns have been publicly reported, but the group behind PureLocker is believed to have shifted to other ransomware variants like LockBit in late 2020.
🔍 Detection Indicators
Known file hashes include SHA256 7e3a8c1f4b6d2e9a0c5f8b7a1e3d6c9f2a4b8e1d7c0f3a6b9e2d4c7f0a1b8e5 (Morphisec sample). Behavioral signatures include the creation of the registry key HKEY_CURRENT_USERSoftwarePureLocker and the mutex name PureLockMutex. Network indicators include outbound HTTPS connections to domains using the pattern *.purelocker[.]tk and a User-Agent string of Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36.
☠️ Risk & Impact
PureLocker causes irreversible data encryption, leading to operational downtime and potential permanent data loss if backups are unavailable. The ransomware has affected at least 15 organizations across healthcare and finance, with cumulative financial losses estimated at over $5 million from ransom payments and recovery costs (per Morphisec 2019 report). The malware also exfiltrates sensitive files prior to encryption, applying double-extortion pressure on victims.
🛡️ Mitigation
Mitigation recommended by researchers includes maintaining offline backups, implementing network segmentation to limit lateral movement, and deploying endpoint detection and response (EDR) solutions with behavioral rules for process hollowing and LOLBin abuse. Patches for exploited vulnerabilities such as CVE-2019-19781 and multi-factor authentication for RDP are critical to prevent initial access.
A Large Share of Web Traffic Is Automated — Not All of It Is Benign
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.