WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home H2OSecCon 2026 Threat Awareness – PureCrypter Malware Downloader Leads to Ransomware and Other Malicious Activity
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Community Partners
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

Threat Awareness – PureCrypter Malware Downloader Leads to Ransomware and Other Malicious Activity

Author: Alec Davison

Created: Tuesday, February 28, 2023 - 19:11

Categories: Cybersecurity

An unknown threat actor is utilizing the PureCrypter malware downloader to infect government organizations with information stealers and various ransomware strains, according to researchers at Menlo Security.

According to the researchers, the observed PureCrypter campaign has targeted multiple government organizations in North America and the Asia-Pacific regions. The threat actor is exploiting Discord to host the initial payload and also compromised a non-profit organization to store additional hosts used in the campaign. “The campaign was found to have delivered several types of malware including Redline Stealer, AgentTesla, Eternity, Blackmoon and Philadelphia Ransomware,” the researchers note. The attack chain begins with an email that leads to a PureCrypter sample in a password-protected ZIP archive. When executed, PureCrypter (in this oberseved attack) downloads AgentTesla backdoor malware that allows attackers to conduct further malicious activity on the compromised device or network. Access the full report at Menlo Security here or read a related article at BleepingComputer.

Related Resources

Members Only

(TLP:AMBER) DHS Office of Intelligence and Analysis Reports (May 21, 2026)

May 21, 2026 in Cybersecurity, Federal & State Resources, Security Preparedness

(TLP:CLEAR) Weekly Vulnerabilities to Prioritize – May 21, 2026

May 21, 2026 in Cybersecurity, Security Preparedness
Members Only

(TLP:GREEN) PEAR Ransomware Claims U.S. Drinking Water Utility as Victim

May 21, 2026 in Cybersecurity, Security Preparedness

Become a Member
FAQs
About
Report Incident

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar