WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home Posts Threat Awareness – PureCrypter Malware Downloader Leads to Ransomware and Other Malicious Activity
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Community Partners
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

Threat Awareness – PureCrypter Malware Downloader Leads to Ransomware and Other Malicious Activity

Author: Alec Davison

Created: Tuesday, February 28, 2023 - 19:11

Categories: Cybersecurity

An unknown threat actor is utilizing the PureCrypter malware downloader to infect government organizations with information stealers and various ransomware strains, according to researchers at Menlo Security.

According to the researchers, the observed PureCrypter campaign has targeted multiple government organizations in North America and the Asia-Pacific regions. The threat actor is exploiting Discord to host the initial payload and also compromised a non-profit organization to store additional hosts used in the campaign. “The campaign was found to have delivered several types of malware including Redline Stealer, AgentTesla, Eternity, Blackmoon and Philadelphia Ransomware,” the researchers note. The attack chain begins with an email that leads to a PureCrypter sample in a password-protected ZIP archive. When executed, PureCrypter (in this oberseved attack) downloads AgentTesla backdoor malware that allows attackers to conduct further malicious activity on the compromised device or network. Access the full report at Menlo Security here or read a related article at BleepingComputer.

Related Resources

Members Only

(TLP:AMBER+STRICT) Situation Report: Heightened Threat Environment – Potential Retaliation by Iranian Threat Actors Following U.S. Strikes on Iran (Updated June 18, 2026)

Jun 18, 2026 in Cybersecurity, OT-ICS Security, Physical Security, Security Preparedness
Members Only

(TLP:AMBER) IOC Associated with Volt Typhoon Performed Network Enumeration on Utah Infrastructure

Jun 18, 2026 in Cybersecurity, Federal & State Resources, Security Preparedness

(TLP:CLEAR) Email Impersonation Remains a Persistent Risk for Water Utilities

Jun 18, 2026 in Cybersecurity, Security Preparedness

Become a Member
FAQs
About
Report Incident
Traffic Light Protocol (TLP)

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar