Zscaler cybersecurity researchers have uncovered a new malware campaign that leverages the PureCrypter malware loader to deliver the DarkVision RAT .

The activity was detected in July 2024 and involves a multi-stage process for delivering the RAT payload.
“ The DarkVision RAT communicates with the command and control (C2) server using a custom network protocol over sockets ,” security researcher Muhammed Irfan VA said in an analysis. The researcher explained that the DarkVision RAT supports various commands and plugins.
See also: TrickMo malware steals Android PINs via fake lock screen
The PureCrypter loader, first discovered in 2022, is an off-the-shelf malware loader available for sale that offers customers the ability to distribute information stealers, RATs, and ransomware.
Researchers are unsure of how PureCrypter is initially delivered, although it paves the way for a .NET executable that is responsible for decrypting and launching the open-source Donut loader.
The Donut loader then proceeds to launch PureCrypter, which ultimately “unpacks” and loads the DarkVision RAT, while also ensuring persistence and adding file paths and process names used by the RAT to the Microsoft Defender Antivirus exception list.
DarkVision first appeared in 2020, advertised on a clearnet website and offered for just $60. It can help cybercriminals with little technical knowledge enhance their attacks.
The RAT comes equipped with an extensive set of features that allow process injection, remote shell, reverse proxy, clipboard manipulation, keylogging, screenshot taking, cookie theft, password resetting from web browsers , and more.
See also: Ukrainian admits he was behind Raccoon Stealer malware
It is also designed to collect system information and receive additional plugins sent from a C2 server. Thanks to these capabilities, the malware and its operators gain full control over the infected Windows computer.
“The DarkVision RAT is a powerful and versatile tool for cybercriminals, offering a wide range of malicious capabilities, from keylogging and screenshot capture to password theft and remote code execution,” Zscaler said.
Its capabilities combined with the low price have made it an extremely popular tool.

What are the best methods for protecting against RAT malware?
The first and most important method of protection is awareness and education. Users need to be aware of the techniques attackers use to spread malware so they can identify and avoid them.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Installing reliable security is another essential method of malware protection. This software should include antivirus, anti-spyware, and anti-malware features, as well as phishing protection.
See also: Linux malware “perfctl” used for cryptomining
It's also important to keep your operating system and all applications up to date. Updates include security that can protect your computer from the latest threats.
Finally, careful interaction with emails and file attachments is crucial. Never open attachments or click on links from unknown sources as they may contain malware.
Source: thehackernews.com
