Close Menu
    Main Menu
    • Home
    • News
    • Tech
    • Robotics
    • ML & Research
    • AI
    • Digital Transformation
    • AI Ethics & Regulation
    • Thought Leadership in AI

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Hacker attackieren Vergabeportal für öffentliche Aufträge

    October 15, 2025

    Greatest robotic vacuum deal: Save $355 on Ecovacs Deebot X9 Professional Omni

    October 15, 2025

    Futures of Work ~ Reflections and suggestions from the second U.Ok. Impartial Anti-Slavery Commissioner

    October 15, 2025
    Facebook X (Twitter) Instagram
    UK Tech InsiderUK Tech Insider
    Facebook X (Twitter) Instagram
    UK Tech InsiderUK Tech Insider
    Home»AI Ethics & Regulation»Researchers Expose SVG and PureRAT Phishing Threats Concentrating on Ukraine and Vietnam
    AI Ethics & Regulation

    Researchers Expose SVG and PureRAT Phishing Threats Concentrating on Ukraine and Vietnam

    Declan MurphyBy Declan MurphySeptember 27, 2025No Comments3 Mins Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Reddit
    Researchers Expose SVG and PureRAT Phishing Threats Concentrating on Ukraine and Vietnam
    Share
    Facebook Twitter LinkedIn Pinterest Email Copy Link


    Sep 26, 2025Ravie LakshmananMalware / Cryptocurrency

    A brand new marketing campaign has been noticed impersonating Ukrainian authorities companies in phishing assaults to ship CountLoader, which is then used to drop Amatera Stealer and PureMiner.

    “The phishing emails include malicious Scalable Vector Graphics (SVG) recordsdata designed to trick recipients into opening dangerous attachments,” Fortinet FortiGuard Labs researcher Yurren Wan mentioned in a report shared with The Hacker Information.

    Within the assault chains documented by the cybersecurity firm, the SVG recordsdata are used to provoke the obtain of a password-protected ZIP archive, which comprises a Compiled HTML Assist (CHM) file. The CHM file, when launched, prompts a sequence of occasions that culminate within the deployment of CountLoader. The e-mail messages declare to be a discover from the Nationwide Police of Ukraine.

    CountLoader, which was the topic of a current evaluation by Silent Push, has been discovered to drop varied payloads like Cobalt Strike, AdaptixC2, and PureHVNC RAT. On this assault chain, nevertheless, it serves as a distribution vector for Amatera Stealer, a variant of ACRStealer, and PureMiner, a stealthy .NET cryptocurrency miner.

    DFIR Retainer Services

    It is price declaring that each PureHVNC RAT and PureMiner are a part of a broader malware suite developed by a menace actor generally known as PureCoder. Among the different merchandise from the identical writer embrace –

    • PureCrypter, a crypter for Native and .NET
    • PureRAT (aka ResolverRAT), a successor to PureHVNC RAT
    • PureLogs, an data stealer and logger
    • BlueLoader, a malware that may act as a botnet by downloading and executing payloads remotely
    • PureClipper, a clipper malware that substitutes cryptocurrency addresses copied into the clipboard with attacker-controlled pockets addresses to redirect transactions and steal funds

    In accordance with Fortinet, Amatera Stealer and PureMiner are each deployed as fileless threats, with the malware “executed through .NET Forward-of-Time (AOT) compilation with course of hollowing or loaded immediately into reminiscence utilizing PythonMemoryModule.”

    Amatera Stealer, as soon as launched, gathers system data, collects recordsdata matching a predefined record of extensions, and harvests information from Chromium- and Gecko-based browsers, in addition to functions like Steam, Telegram, FileZilla, and varied cryptocurrency wallets.

    “This phishing marketing campaign demonstrates how a malicious SVG file can act as an HTML substitute to provoke an an infection chain,” Fortinet mentioned. On this case, attackers focused Ukrainian authorities entities with emails containing SVG attachments. The SVG-embedded HTML code redirected victims to a obtain website.”

    The event comes as Huntress uncovered a probable Vietnamese-speaking menace group utilizing phishing emails bearing copyright infringement discover themes to trick recipients into launching ZIP archives that result in the deployment of PXA Stealer, which then evolves right into a multi-layered an infection sequence dropping PureRAT.

    CIS Build Kits

    “This marketing campaign demonstrates a transparent and deliberate development, beginning with a easy phishing lure and escalating by layers of in-memory loaders, protection evasion, and credential theft,” safety researcher James Northey mentioned. “The ultimate payload, PureRAT, represents the fruits of this effort: a modular, professionally developed backdoor that provides the attacker full management over a compromised host.”

    “Their development from amateurish obfuscation of their Python payloads to abusing commodity malware like PureRAT reveals not simply persistence, but additionally hallmarks of a severe and maturing operator.”

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Declan Murphy
    • Website

    Related Posts

    Hacker attackieren Vergabeportal für öffentliche Aufträge

    October 15, 2025

    Microsoft Limits IE Mode in Edge After Chakra Zero-Day Exercise Detected

    October 15, 2025

    Chinese language Hackers Exploit ArcGIS Server as Backdoor for Over a 12 months

    October 14, 2025
    Top Posts

    Evaluating the Finest AI Video Mills for Social Media

    April 18, 2025

    Utilizing AI To Repair The Innovation Drawback: The Three Step Resolution

    April 18, 2025

    Midjourney V7: Quicker, smarter, extra reasonable

    April 18, 2025

    Meta resumes AI coaching utilizing EU person knowledge

    April 18, 2025
    Don't Miss

    Hacker attackieren Vergabeportal für öffentliche Aufträge

    By Declan MurphyOctober 15, 2025

    Prorussische Hacker haben die Internetseite des Deutschen Vergabeportals quick eine Woche lang lahmgelegt.ozrimoz – shutterstock…

    Greatest robotic vacuum deal: Save $355 on Ecovacs Deebot X9 Professional Omni

    October 15, 2025

    Futures of Work ~ Reflections and suggestions from the second U.Ok. Impartial Anti-Slavery Commissioner

    October 15, 2025

    Information Analytics Automation Scripts with SQL Saved Procedures

    October 15, 2025
    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo

    Subscribe to Updates

    Get the latest creative news from SmartMag about art & design.

    UK Tech Insider
    Facebook X (Twitter) Instagram
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms Of Service
    • Our Authors
    © 2025 UK Tech Insider. All rights reserved by UK Tech Insider.

    Type above and press Enter to search. Press Esc to cancel.