Threats Tagged 'purehvnc'
View all threats tagged with 'purehvnc'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'purehvnc'
Click on any threat for detailed analysis and mitigation recommendations
Between August and October 2025, a phishing campaign targeted Colombian users by impersonating the Attorney General's office to deliver the PureHVNC Remote Access Trojan (RAT) via the Hijackloader malware loader. The attack chain involved sophisticated techniques such as DLL side-loading, anti-virtual machine checks, and multiple code injection methods to evade detection and maintain persistence. This campaign marks the first known use of Hijackloader to deliver PureHVNC in Spanish-speaking Latin America, signaling an evolution in regional threat actor tactics. Although primarily focused on Colombia, the use of phishing and advanced evasion techniques poses a risk to organizations with similar user profiles or language contexts. The campaign's medium severity reflects the complexity and potential for unauthorized remote access but lacks evidence of widespread exploitation beyond the initial targets. Defenders should prioritize user awareness, advanced endpoint detection, and monitoring for indicators of DLL side-loading and unusual process injections. No CVSS score is available; based on impact and exploitation complexity, the threat is assessed as medium severity. Join the discussion | AlienVault OTX General | 10/31/2025, 09:32:15 UTC Added: 10/31/2025, 11:09:16 UTC |
A new malware loader discovered in May 2025 executes two malware families: TorNet and PureHVNC. The loader uses API hashing with MurmurHash2 and implements persistence through registry modifications. It decrypts and decompresses payloads using AES-128-ECB and LZMA, then injects them into a suspended jsc.exe process. TorNet, a downloader malware, communicates via TOR network, while PureHVNC is a commercial RAT allowing remote access. Both malware use Protocol Buffers for configuration deserialization. The loader's unique characteristics include its dual payload execution and API hashing implementation, indicating potential future attack techniques. Join the discussion | AlienVault OTX General | 10/31/2025, 09:31:55 UTC Added: 10/31/2025, 11:09:16 UTC |
A new malware loader named CountLoader has been identified, strongly associated with Russian ransomware gangs. It comes in three versions: .NET, PowerShell, and JScript. The threat is believed to be part of an Initial Access Broker's toolset or used by a ransomware affiliate linked to LockBit, BlackBasta, and Qilin groups. CountLoader was recently employed in a phishing campaign targeting Ukrainian citizens, impersonating the Ukrainian police. The loader attempts to connect to multiple C2 servers, downloads and executes various malware payloads, and uses advanced techniques to evade detection. It has been observed dropping CobaltStrike and AdaptixC2, among other malicious tools. The malware's functionality includes system information gathering, persistence mechanisms, and multiple download methods. Join the discussion | AlienVault OTX General | 09/19/2025, 08:57:24 UTC Added: 09/19/2025, 10:42:28 UTC |
A sophisticated phishing campaign has been identified, utilizing carefully crafted emails to deliver malicious URLs linked to convincing phishing pages. These pages entice recipients to download JavaScript files that act as droppers for UpCrypter, a malware that ultimately deploys various remote access tools (RATs). The attack chain begins with obfuscated scripts redirecting victims to spoofed sites personalized with the target's email domain. The campaign uses different lures, including voicemail-themed and purchase order-themed emails. UpCrypter, the central loader framework, stages and deploys multiple RATs, including PureHVNC, DCRat, and Babylon RAT. The malware employs anti-VM and anti-analysis techniques, downloads additional payloads, and establishes persistence. This campaign operates globally, affecting multiple industries, and demonstrates an adaptable threat delivery ecosystem capable of bypassing defenses and maintaining persistence across different environments. Join the discussion | AlienVault OTX General | 08/26/2025, 00:06:09 UTC Added: 08/26/2025, 07:47:43 UTC |
A wide-ranging phishing campaign has been identified that enables threat actors to bypass traditional security controls and delay detection. The campaign, tracked since 2024, has facilitated remote surveillance, credential theft, lateral movement, data exfiltration, and ransomware across numerous organizations. The likely new or rebranded cybercriminal group behind this campaign uses legitimate services like TryCloudflare to host and deliver highly evasive malware such as AsyncRAT and other Remote Access Trojans. This malware allows threat actors to remotely control infected networks throughout the full attack lifecycle. The campaign targets organizations globally across multiple sectors without industry preference, using widely available malware and difficult-to-detect techniques involving Python scripts, obfuscated batch scripts, trusted cloud services, and dynamic infrastructure. Join the discussion | AlienVault OTX General | 06/17/2025, 20:39:06 UTC Added: 06/18/2025, 11:34:31 UTC |
A threat actor has orchestrated a sophisticated malvertising campaign impersonating Kling AI, a popular AI-powered image and video synthesis tool. The attackers use counterfeit Facebook pages and paid ads to drive traffic to a convincing fake website. Users are tricked into downloading malicious files disguised as AI-generated media, which are actually executable loaders. These loaders employ advanced evasion techniques, including .NET Native AOT compilation, and deploy infostealers with extensive monitoring capabilities. The campaign has a global reach, particularly targeting users in Asia, and exploits the growing popularity of AI content generation platforms. The malware focuses on stealing credentials, session tokens, and monitoring crypto-related activities across multiple browsers and applications. Join the discussion | AlienVault OTX General | 05/21/2025, 15:37:57 UTC Added: 05/21/2025, 15:52:54 UTC |
Showing 1 to 6 of 6 results