Skip to main content
Mallory
9 malware families

PureCoder

Also known asPureCoder

PureCoder is the developer and seller of the commercial malware family centered on the PureLogs .NET information stealer. Reported offerings associated with PureCoder include PureLogs, PureCrypter, PureMiner, PureHVNC, and a botnet referred to as BlueLoader. PureLogs is described as a commodity .NET stealer used by multiple threat actors and sold via the actor’s website. It is designed to steal browser data such as passwords, cookies, history, autofill data, and extensions; cryptocurrency wallet data from wallets including Armory, Atomic, BitcoinCore, DashCore, Electrum, Ethereum, Exodus, Jaxx, LitecoinCore, Monero, and Zcash; and tokens or credentials from applications including Discord, Telegram, Steam, Outlook, Thunderbird, Pidgin, OpenVPN, and ProtonVPN. Supporting reporting also states that PureLogs can be launched by VMDetectLoader, which performs persistence, environment checks, and execution of the stealer. In one observed December 14, 2022 spam campaign targeting users in Italy, a separate threat actor identified as Alibaba2044 delivered PureLogs via a password-protected ZIP containing a CAB file disguised as a BAT file, which dropped a .NET loader that decrypted the PureLogs DLL in memory and loaded it using .NET Assembly.Load(). Observed ATT&CK techniques in that campaign included user execution, deobfuscation/decoding, defense impairment, system and file discovery, automated collection, local data theft, application-layer C2, and automated exfiltration. No nation-state attribution is stated in the provided content.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

MITRE ATT&CK

Tradecraft

2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

1 of 15 tactics2 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0005
Stealth
2 techniques
T1027
Obfuscated Files or Information
T1140
Deobfuscate/Decode Files or Information
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping2

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal9

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables

Domains, IPs, and hashes tied to this actor, refreshed continuously.