PureRAT Campaign Uses PNGs for Stealthy Fileless Attacks
Article Content
- •PureRAT hides malicious payloads in PNG files for stealthy execution.
- •The malware operates entirely in memory, complicating detection and forensics.
- •Windows systems are primarily targeted, with ongoing campaign activity reported.
A new malware campaign utilizing the PureRAT remote access trojan (RAT) has been identified, targeting Windows systems. This sophisticated attack hides malicious portable executable (PE) payloads within PNG image files, allowing for fileless execution that significantly complicates detection efforts. The campaign employs advanced techniques such as steganography, PowerShell-based loaders, UAC bypass, process hollowing, and anti-virtualization checks to evade security measures. The initial infection vector is a weaponized .LNK file that initiates the attack. As the malware operates entirely in memory, it leaves minimal traces on compromised systems, making forensic analysis challenging. Organizations using Windows systems are particularly vulnerable to this stealthy threat. The current status of the campaign indicates ongoing activity, with no specific mitigation strategies disclosed in the articles.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track PureRAT in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
CVE-2026-93425: Dokploy PaaS Critical RCE Leads to Container Root and Host Compromise TheHackerWire / 1d Telemetry Metric Intelligence Detail CVE Identifier CVE-2026-93425 CVSS Severity 9.9 CRITICAL Affected Target the Dokploy container Vulnerability Class Security Vulnerability Exploit Availability No Public PoC Indexed EPSS Threat Score Awaiting scoring CISA KEV Status Not Listed in CISA KEV Remediation Status Advisory / Mitigation In Review A critical command injection vulnerability, CVE-2026
Critical Zero-Day Vulnerability in F5 BIG-IP APM Exploited for Remote Code Execution F5 Networks has reported a critical vulnerability in its BIG-IP Access Policy Manager (APM), tracked as CVE-2026-94127, which is being actively exploited in the wild. The flaw allows unauthenticated attackers to execute remote code on systems configured with both an APM access policy and an OAuth profile. This…