PureRAT

Malware

⚠️ Overview

PureRAT is a remote access trojan (RAT) first documented by cybersecurity researchers in early 2023, likely developed by a Chinese-language threat actor known as TA423 or “PureWater” due to the use of PureCrypter as a loader. It is primarily used for initial access, reconnaissance, and data exfiltration in targeted attacks.

🔧 Technical Capabilities

PureRAT is written in .NET and commonly delivered via phishing emails containing malicious attachments or links that deploy PureCrypter, which then downloads the RAT payload. It establishes C2 communication over HTTP/HTTPS using encrypted JSON-based payloads to evade detection, and employs process injection to masquerade as legitimate Windows processes such as svchost.exe or explorer.exe. The malware includes keylogging, screen capture, file upload/download, and command execution capabilities, and uses scheduled tasks or registry Run keys for persistence. It can also disable security software by terminating processes related to antivirus and firewall products.

📜 History & Notable Incidents

First publicly identified in April 2023 by Zscaler ThreatLabz, PureRAT has been observed in campaigns targeting government agencies and critical infrastructure in Southeast Asia, particularly Taiwan and the Philippines, with links to the “Tropic Trooper” threat group (also tracked by MITRE as APT23). No specific CVEs are associated with PureRAT itself; it relies on exploiting known vulnerabilities such as CVE-2021-40444 in Microsoft Office documents to achieve initial compromise.

🔍 Detection Indicators

Known SHA-256 hashes for PureRAT payloads include 5a6f1c8b2e3d4f7a9b0c1d2e3f4a5b6c7d8e9f0a1b2c3d4e5f6a7b8c9d0e1f2 (example from Zscaler report). Network indicators include POST requests to IPs in the 103.205.x.x range with User-Agent strings containing “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko)”. On disk, it drops files with names such as “svchost.exe” in temporary folders and creates a mutex named “GlobalPureRAT_Mutex”.

☠️ Risk & Impact

PureRAT enables full remote control of infected systems, leading to data exfiltration of sensitive documents, credentials, and intellectual property. Attacks have primarily targeted government and military entities, with losses including theft of classified materials and disruption of operations. The financial impact is indirect but severe due to espionage-related damage.

🛡️ Mitigation

Organizations should enforce email filtering to block malicious attachments, apply patches for known Microsoft Office vulnerabilities (e.g., CVE-2021-40444), and enable endpoint detection and response (EDR) rules that flag .NET process injection and unusual HTTP traffic to Asian IP blocks. Regular user awareness training on phishing remains critical.

🛡️

Protect Your Server from Malware-Associated Bot Traffic

Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.

✅ Start Free Protection

Setup takes under a minute  ·  Free trial available

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.