PureRAT Attacks Surge 400%: Russian Businesses Face Unprecedented Malware Threat in 2025


# Russian Organizations Targeted by PureRAT Malware in Escalating Phishing Campaign

Russian businesses have fallen victim to a sophisticated phishing campaign distributing PureRAT malware, according to Kaspersky’s recent investigation. The attacks, which began in March 2023, have intensified dramatically with a fourfold increase in the first third of 2025 compared to the same period in 2024.

## Attack Methodology

The campaign begins with phishing emails containing either RAR file attachments or links to archives disguised as legitimate Microsoft Word or PDF documents through double extensions (e.g., “doc_054_[redacted].pdf.rar”). When executed, the malware follows a complex infection chain:

1. The executable copies itself to “%AppData%” as “task.exe” and creates “Task.vbs” in the Startup folder
2. It unpacks “ckcfb.exe” and runs “InstallUtil.exe” to inject the decrypted module
3. “Ckcfb.exe” extracts and decrypts “Spydgozoi.dll” containing the main PureRAT payload

## Malware Capabilities

PureRAT establishes SSL connections with command-and-control servers and transmits system information, including antivirus details, computer name, and system uptime. The C2 server then deploys auxiliary modules with various functions:

– **PluginPcOption**: Executes commands for self-deletion, restart, shutdown, or reboot
– **PluginWindowNotify**: Monitors active windows for keywords like “password” or “bank” to perform unauthorized actions
– **PluginClipper**: Substitutes cryptocurrency wallet addresses in the clipboard with attacker-controlled ones

The Trojan provides comprehensive system access, including file system control, registry manipulation, process management, camera/microphone access, keylogging, and remote desktop functionality.

## Additional Payload: PureLogs Stealer

The attack simultaneously deploys “StilKrip.exe,” a commercial downloader called PureCrypter, which has been active since 2022. This component downloads “Bghwwhmlr.wav,” which ultimately launches PureLogs (“Bftvbho.dll”), an information stealer targeting:

– Web browsers
– Email clients
– VPN services
– Messaging apps
– Cryptocurrency wallets
– Password managers
– File transfer applications

Kaspersky warns that this combination of PureRAT backdoor and PureLogs stealer grants attackers unlimited access to infected systems and confidential organizational data, with email-based phishing remaining the primary attack vector.

Share This Article