HomeSecurityPureHVNC RAT leverages GitHub for source code hosting

PureHVNC RAT leverages GitHub for source code hosting

The PureHVNC RAT remote administration tool has emerged as an advanced component of the Pure malware family, gaining prominence in mid-2025 amid an increase in targeted breach campaigns.

See also: RevengeHotels leverages AI to distribute VenomRAT

PureHVNC RAT

Originating from underground forums and Telegram channels, PureHVNC is being promoted by its creator, known as PureCoder, along with companion tools such as PureCrypter, PureLogs, and PureMiner. Its adoption by cybercriminal clients reflects a growing demand for modular malware suites capable of covert full system control and data extraction.

Initial deployments have leveraged the phishing ClickFix, luring victims with fake job offers to execute malicious scripts, setting the stage for multi-layered breaches. In one notable incident, attackers deployed a Rust Loader, followed by the PureHVNC RAT and the Sliver command-and-control framework within an eight-day window.

Check Point analysts noted that during this campaign, PureHVNC communicated with its control server to retrieve three GitHub URLs that hosted supporting modules, directly implicating the developer's GitHub accounts in the malware's operational infrastructure.

See also: ZynorRAT targets Windows and Linux systems

PureHVNC RAT leverages GitHub for source code hosting

These GitHub repositories contained browser driver executables and plugin files, essential for TwitchBot and YouTubeBot, illustrating an unusual developer-sourced supply chain for malware support files.

Beyond its initial infiltration tactics, PureHVNC demonstrates advanced persistence and privilege escalation capabilities. Once executed, the RAT registers itself via scheduled tasks named to mimic legitimate Google Updater, ensuring resilience across reboots. If executed without administrative privileges, it triggers a UAC elevation loop using PowerShell. Once elevated, the loader creates a mutex (MistyRoseNavy) to prevent re-execution and creates a scheduled task with a retry interval of one minute.

This approach, combined with AMSI bypass via an LdrLoadDll , allows PureHVNC to remain undetected by real-time defenses while maintaining control of the endpoint. The initial loader of PureHVNC is a .NET delivered by the Rust Loader shellcode. The loader decrypts its payload using ChaCha20-Poly1305 , verifies the payload size against a 1 KB limit, and allocates executable memory to accommodate the unencrypted .NET. It is then loaded and executed, initializing the RAT's main loop.

See also: ZynorRAT targets Windows and Linux systems

PureHVNC RAT leverages GitHub for source code hosting

Communication is established over SSL streams, where the bot sends Gzip—including the operating system version, installed antivirus products, and metadata such as the campaign ID—to the C2 server. Incoming commands are received as compressed buffers, decompressed, decomposed, and sent to add-on threads for execution. By segmenting payload delivery and applying encryption and compression, PureHVNC evades static signature detection and complicates network-based discovery, highlighting its stealthy infection mechanism.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS