Close Menu
  • Academy
  • Events
  • Identity
  • International
  • Inventions
  • Startups
    • Sustainability
  • Tech
  • Español
    • Português
What's Hot

DiffusedRive raises $3.5 million to solve the biggest challenges of physical AI: high quality training data

A vulnerability in the Gitlab duo allowed attackers to hijack AI responses with hidden prompts

Do you think India, Pakistan and Iran are all pleading? Taliban | Taliban News

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Academy
  • Events
  • Identity
  • International
  • Inventions
  • Startups
    • Sustainability
  • Tech
  • Español
    • Português
Fyself News
Home » Purerat Malware Spikes 4X will deploy PureLogs to target Russian companies in 2025
Identity

Purerat Malware Spikes 4X will deploy PureLogs to target Russian companies in 2025

userBy userMay 21, 2025No Comments3 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

May 21, 2025Ravi LakshmananMalware/Windows Security

According to new Kaspersky surveys, Russian organizations have become targets for phishing campaigns that distribute malware called Purerat.

“The Russian business-oriented campaign began in March 2023, but in the first third of 2025, the number of attacks was quadrupled in comparison to the same period in 2024,” the cybersecurity vendor said.

Attack chains not attributable to a particular threat actor will start with a phishing email containing attachments to RAR files or links to archives that masquerade Microsoft Word or PDF documents (“doc_054_[redacted].pdf.rar “).

What resides in the archive file is an executable that, upon launch, copies itself to the “%appData%” position of the compromised Windows machine under the name “task.exe” and creates a visual basic script called “task.vbs” in the startup vbs folder.

Cybersecurity

The executable file unzips another executable file “ckcfb.exe”, runs the system utility “installutil.exe” and injects it into the decrypted module. For “CKCFB.EXE”, the part of which extracts and decrypts the DLL file “Spydgozoi.dll”, which incorporates the main payload of the Purerat malware.

Purerat establishes an SSL connection on the Command and Control (C2) server and sends system information including system information, computer name, and details of how long it has passed since the system started up. In response, the C2 server sends an auxiliary module to perform various malicious actions –

PluginPcoption allows you to run self-exclusion commands, restart the executable, and shut down or restart the plug of your computer, like computer plugin windowdown. I used something that was controlled by the attacker and copied it to the system clipboard

“The Trojan includes modules for downloading and running any file that provides full access to file systems, registry, processes, cameras and microphones, implementing keylogger functionality and allowing attackers to secretly control their computers using the principles of remote desktop,” says Kaspersky.

The original executable that launches “CKCFB.exe” simultaneously also extracts a second binary called “Stilkrip.exe”. It has been active since 2022.

Cybersecurity

“stillkrip.exe” is designed to download “bghwwhmlr.wav”. This follows the attack sequence mentioned above, running “installutil.exe” and eventually launching “ttcxxewxtly.exe”.

PureLogs is a ready-made information steel person who can collect data from web browsers, email clients, VPN services, messaging apps, wallet browser extensions, password managers, cryptocurrency wallet apps, and programs such as Filezilla and WinSCP.

“Purerat Backdoor and Purelogs Stealer have a wide range of features that allow attackers to have unlimited access to data from infected systems and sensitive organizations,” Kaspersky said. “The main vector of attacks on businesses is emails with malicious attachments and links that remain.”

Did you find this article interesting? Follow us on Twitter and LinkedIn to read exclusive content you post.

Source link

Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleThena launches V3,3 with modular fluidity layer for BNB chains
Next Article Shopify launches AI-powered store builders as part of the latest update
user
  • Website

Related Posts

A vulnerability in the Gitlab duo allowed attackers to hijack AI responses with hidden prompts

May 23, 2025

Chinese hackers exploit Trimble CityWorks flaws to infiltrate US government networks

May 22, 2025

Critical Windows Server 2025 DMSA vulnerability allows for active directory compromise

May 22, 2025
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

DiffusedRive raises $3.5 million to solve the biggest challenges of physical AI: high quality training data

A vulnerability in the Gitlab duo allowed attackers to hijack AI responses with hidden prompts

Do you think India, Pakistan and Iran are all pleading? Taliban | Taliban News

Russia-Ukraine War: List of Major Events, Day 1,184 | News of the Russian-Ukraine War

Trending Posts

Do you think India, Pakistan and Iran are all pleading? Taliban | Taliban News

May 23, 2025

Russia-Ukraine War: List of Major Events, Day 1,184 | News of the Russian-Ukraine War

May 23, 2025

Florida court orders former Mexican security chief to pay millions of people to Mexico | Court News

May 23, 2025

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

DiffusedRive raises $3.5 million to solve the biggest challenges of physical AI: high quality training data

Top Startup and Tech Funding News – May 22, 2025

Apple, who will launch smart glasses in 2026 as part of API push, drops plans for camera-equipped smartwatch

Psy develops the first unreliable bridge from Dogecoin to Solana

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2025 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.