Malware.View on attack.mitre.org
PureCrypter is a fully-featured malware loader, developed by a threat actor called “PureCoder," that has been in use since at least 2021 to distribute a variety of remote access trojans and information stealers.
| Technique | Procedure example |
|---|---|
| T1027.013 Encrypted/Encoded File |
PureCrypter has used SmartAssembly and NET-Reactor for string encryption and control flow obfuscation. |
| T1027.016 Junk Code Insertion |
PureCrypter can insert junk code to avoid detection. |
| T1033 System Owner/User Discovery |
PureCrypter can retrieve the username from targeted machines. |
| T1036.005 Match Legitimate Resource Name or Location |
PureCrypter has used multiple file names to appear legitimate such as firefox\firefox.exe, Google\chrome.exe, and Taskmgr.exe. |
| T1036.008 Masquerade File Type |
PureCrypter has used a .NET downloader named 63342221.BAT and has used .jpg, .png, and .log as false extensions for malicious files. |
| T1053.005 Scheduled Task |
PureCrypter can maintain persistence with scheduled tasks. |
| T1055 Process Injection |
PureCrypter can inject its final stage into another process on the targeted system. |
| T1057 Process Discovery |
PureCrypter can enumerate processes on compromised hosts. |
| T1059.001 PowerShell |
PureCrypter can execute PowerShell commands to exclude files from EDR and to self-delete. |
| T1070.004 File Deletion |
PureCrypter can execute a PowerShell command to self-delete. |
| T1082 System Information Discovery |
PureCrypter can enumerate a targeted system's SerialNumber and Version. |
| T1102 Web Service |
PureCrypter can use Telegram or Discord to send infection status messages. |
| T1105 Ingress Tool Transfer |
PureCrypter can download additional payloads for execution on the compromised host. |
| T1140 Deobfuscate/Decode Files or Information |
PureCrypter can decrypt downloaded resources and parse internal files to determine its settings. |
| T1480 Execution Guardrails |
PureCrypter code contains an ExclusionRegionNames option where it can compare the results of `kernel32!GetGeoInfo` with a list of regions. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.