Skip to content
ThreatCluster

PureRAT Campaign Uses PNGs for Stealthy Fileless Attacks

First seen 21 Apr 2026, 15:30 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •April 22, 2026 at 15:18 UTC
  • •PureRAT hides malicious payloads in PNG files for stealthy execution.
  • •The malware operates entirely in memory, complicating detection and forensics.
  • •Windows systems are primarily targeted, with ongoing campaign activity reported.

A new malware campaign utilizing the PureRAT remote access trojan (RAT) has been identified, targeting Windows systems. This sophisticated attack hides malicious portable executable (PE) payloads within PNG image files, allowing for fileless execution that significantly complicates detection efforts. The campaign employs advanced techniques such as steganography, PowerShell-based loaders, UAC bypass, process hollowing, and anti-virtualization checks to evade security measures. The initial infection vector is a weaponized .LNK file that initiates the attack. As the malware operates entirely in memory, it leaves minimal traces on compromised systems, making forensic analysis challenging. Organizations using Windows systems are particularly vulnerable to this stealthy threat. The current status of the campaign indicates ongoing activity, with no specific mitigation strategies disclosed in the articles.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 156d ago How this analysis works

Timeline

2026-04-21
PureRAT campaign reported by cybersecurity news outlets.

More articles in this cluster (2)

Following this threat?

Track PureRAT in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed