PureCrypter — Malware Profile
PureCrypter is a fully-featured malware loader, developed by a threat actor called “PureCoder," that has been in use since at least 2021 to distribute a variety of remote access trojans and information stealers.
MITRE ATT&CK techniques (26)
- T1027.013 Encrypted/Encoded File
- T1027.016 Junk Code Insertion
- T1033 System Owner/User Discovery
- T1036.005 Match Legitimate Resource Name or Location
- T1036.008 Masquerade File Type
- T1053.005 Scheduled Task
- T1055 Process Injection
- T1057 Process Discovery
- T1059.001 PowerShell
- T1070.004 File Deletion
- T1082 System Information Discovery
- T1102 Web Service
- T1105 Ingress Tool Transfer
- T1140 Deobfuscate/Decode Files or Information
- T1480 Execution Guardrails
- T1480.002 Mutual Exclusion
- T1518.001 Security Software Discovery
- T1547.001 Registry Run Keys / Startup Folder
- T1564.003 Hidden Window
- T1573.001 Symmetric Cryptography
- T1573.002 Asymmetric Cryptography
- T1614 System Location Discovery
- T1622 Debugger Evasion
- T1673 Virtual Machine Discovery
- T1678 Delay Execution
- T1685 Disable or Modify Tools