Threats Tagged 'purerat'
View all threats tagged with 'purerat'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'purerat'
Click on any threat for detailed analysis and mitigation recommendations
Since April 2026, a sophisticated multi-stage intrusion campaign has targeted hospitality and hotel organizations across Europe and Asia. The operation uses photo-themed ZIP archives containing malicious shortcut files disguised as images. When executed, these shortcuts initiate an attack chain involving obfuscated PowerShell, Node.js-based implants, and dual registry persistence mechanisms. The threat actor exploits legitimate services like Calendly and Google redirects for phishing delivery, employing authentication laundering to bypass email security controls. The campaign evolved through two waves, introducing .NET DLL compilation, Cloudflare-fronted infrastructure, and refined obfuscation techniques. Post-compromise activities include command-and-control beaconing over non-standard ports, forced shutdowns, and portable executable compilation, suggesting preparation for additional malicious operations. Join the discussion | AlienVault OTX General | 06/26/2026, 03:57:11 UTC Added: 06/26/2026, 08:46:01 UTC |
A Vietnamese threat actor is employing AI to develop code for an ongoing phishing campaign delivering PureRAT malware and other payloads. The attacks begin with phishing emails disguised as job opportunities, potentially targeting work computers. The attacker's use of AI is evidenced by detailed comments and numbered steps in scripts, as well as instructions in debug messages. The attack chain involves malicious archives, sideloaded DLLs, and batch scripts likely authored using AI. The attacker appears to be continually refining their methods and may be selling access to compromised organizations. This case demonstrates how AI can lower the barrier to entry for less skilled attackers, helping them write code and build attack toolkits. Join the discussion | AlienVault OTX General | 01/28/2026, 17:20:03 UTC Added: 01/28/2026, 18:50:56 UTC |
A sophisticated phishing campaign targets Booking.com hotel partners and their customers by compromising hotel administrators' systems with malware such as PureRAT. Attackers gain access to booking management accounts and use spear-phishing emails impersonating Booking.com to trick guests into paying twice for reservations. The campaign employs social engineering tactics, malicious sites, and a complex infrastructure involving compromised legitimate websites and bulletproof hosting. This operation is part of a broader cybercrime ecosystem offering specialized services to facilitate attacks on booking platforms. The threat impacts the confidentiality and financial integrity of hotel bookings and customer payments. European hospitality businesses relying on Booking.com, especially in countries with large tourism sectors, are at risk. Mitigation requires targeted security controls on hotel admin systems, user awareness training, and monitoring for unusual booking activities. Join the discussion | AlienVault OTX General | 11/07/2025, 09:22:49 UTC Added: 11/07/2025, 09:36:10 UTC |
This report analyzes a malware campaign initially identified as a Python-based infostealer that ultimately leads to the deployment of PureRAT, a commercially available remote access trojan (RAT). The campaign involves multiple stages and tools, including various loaders and stealers, culminating in full RAT capabilities. Indicators such as IP addresses and file hashes are provided for detection and blocking. No specific affected software versions or CVEs are identified. The threat is assessed as medium severity due to its capability to escalate from information theft to full remote access. Join the discussion | AlienVault OTX General | 10/10/2025, 20:35:52 UTC Added: 10/10/2025, 20:36:29 UTC |
A Vietnamese threat actor has transitioned from using the PXA Stealer to deploying PureRAT, a commercial remote access trojan. The attack chain involves multiple stages, including phishing emails, Python-based infostealers, and .NET loaders. The campaign demonstrates a progression in complexity, utilizing DLL sideloading, obfuscation techniques, and defense evasion methods. The final payload, PureRAT, provides the attacker with extensive control over compromised systems. The threat actor's shift to commodity malware indicates a maturing operation, lowering the barrier for sophisticated attacks. This evolution highlights the need for robust, multi-layered defense strategies to counter such adaptable threats. Join the discussion | AlienVault OTX General | 10/10/2025, 08:25:09 UTC Added: 10/10/2025, 08:36:17 UTC |
Showing 1 to 5 of 5 results