All news with #purecoder tag
Fri, September 26, 2025
Researchers Expose SVG and PureRAT Phishing Threats
#Phishing
#Information Stealer
#PureCoder
#PureRAT
#Amatera Stealer
#PureMiner
#CountLoader
#Fortinet
📧 Fortinet FortiGuard Labs and other researchers detailed phishing campaigns that weaponize malicious SVG attachments to initiate downloads of password-protected ZIP archives and Compiled HTML Help (CHM) files. Those CHM files activate loader chains that deliver CountLoader as a distribution stage for Amatera Stealer and the stealthy .NET miner PureMiner, both run filelessly via .NET AOT and memory-loading techniques. Separately, Huntress attributes a Vietnamese-speaking operator using copyright-themed lures that escalate from PXA Stealer to the modular backdoor PureRAT.