ATT&CKSoftwarePureCrypter

PureCrypter

S9019

Malware.View on attack.mitre.org

About this malware

PureCrypter is a fully-featured malware loader, developed by a threat actor called “PureCoder," that has been in use since at least 2021 to distribute a variety of remote access trojans and information stealers.

Techniques used26

Procedure examples26

TechniqueProcedure example
T1027.013
Encrypted/Encoded File

PureCrypter has used SmartAssembly and NET-Reactor for string encryption and control flow obfuscation.

T1027.016
Junk Code Insertion

PureCrypter can insert junk code to avoid detection.

T1033
System Owner/User Discovery

PureCrypter can retrieve the username from targeted machines.

T1036.005
Match Legitimate Resource Name or Location

PureCrypter has used multiple file names to appear legitimate such as firefox\firefox.exe, Google\chrome.exe, and Taskmgr.exe.

T1036.008
Masquerade File Type

PureCrypter has used a .NET downloader named 63342221.BAT and has used .jpg, .png, and .log as false extensions for malicious files.

T1053.005
Scheduled Task

PureCrypter can maintain persistence with scheduled tasks.

T1055
Process Injection

PureCrypter can inject its final stage into another process on the targeted system.

T1057
Process Discovery

PureCrypter can enumerate processes on compromised hosts.

T1059.001
PowerShell

PureCrypter can execute PowerShell commands to exclude files from EDR and to self-delete.

T1070.004
File Deletion

PureCrypter can execute a PowerShell command to self-delete.

T1082
System Information Discovery

PureCrypter can enumerate a targeted system's SerialNumber and Version.

T1102
Web Service

PureCrypter can use Telegram or Discord to send infection status messages.

T1105
Ingress Tool Transfer

PureCrypter can download additional payloads for execution on the compromised host.

T1140
Deobfuscate/Decode Files or Information

PureCrypter can decrypt downloaded resources and parse internal files to determine its settings.

T1480
Execution Guardrails

PureCrypter code contains an ExclusionRegionNames option where it can compare the results of `kernel32!GetGeoInfo` with a list of regions.

View all 26 procedure examples

Groups that use it1

Campaigns0

None recorded.

References1

  1. Zscaler PureCrypter JUN 2022 Open source
    Dumont, R. (2022, June 13). Technical Analysis of PureCrypter: A Fully-Functional Loader Distributing Remote Access Trojans and Information Stealers. Retrieved April 16, 2026.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.