Cyber Security News

Hackers Attacking Organizations with Weaponized RAR Archive to Deliver Pure Malware

A sophisticated malware campaign targeting Russian businesses has intensified significantly in 2025, with attackers leveraging weaponized RAR archives to deliver the dangerous PureRAT backdoor and PureLogs stealer.

These attacks, which began in March 2023, have seen a fourfold increase in the first four months of 2025 compared to the same period last year, indicating a concerning escalation in the threat landscape.

The attack vector relies primarily on spam emails containing malicious attachments in the form of RAR archives, or links to download such archives.

These files employ deceptive naming conventions focused on accounting terminology, including keywords like “doc,” “akt,” “sverka,” “buh,” and “oplata,” often utilizing the double extension technique (.pdf.rar) to trick unsuspecting users into executing malicious code.

This social engineering approach specifically targets financial departments within organizations, where employees regularly handle documents with similar names.

Securelist researchers identified that upon execution, the malware employs a multi-stage infection process designed to evade detection while establishing persistence.

The initial RAR archive contains an executable disguised as a PDF document that, when launched, initiates a complex chain of events leading to the deployment of both PureRAT backdoor and PureLogs stealer components, giving attackers comprehensive control over infected systems.

PureLogs Infection Scheme (Source – Securelist)

The PureRAT malware operates on a Malware-as-a-Service model, making it accessible to various threat actors who can purchase and deploy it according to their objectives.

This accessibility partially explains the dramatic increase in attacks, as more cybercriminals gain access to sophisticated attack tools without needing advanced technical skills.

Infection Mechanism

The infection begins when a user opens the disguised executable from the RAR archive.

Infection scheme (Source – Securelist)

The file immediately copies itself to %AppData% under the name Task.exe and creates an autorun VBS script (Task.vbs) in the Startup folder with a simple but effective command:-

CreateObject("WScript.Shell").Run """C:\Users\\AppData\Roaming\Task.exe"""

The malware then extracts StilKrip.exe from its embedded resources and launches it while simultaneously extracting and decrypting Ckcfb.exe.

This module is injected into the legitimate Windows InstallUtil.exe process to avoid detection. Ckcfb.exe proceeds to extract and decrypt the Spydgozoi.dll library containing the main PureRAT backdoor functionality.

Communication with command and control servers is established through SSL connections, with messages transmitted in protobuf format and compressed using gzip.

These messages contain comprehensive system information, including the infected device identifier, installed antivirus product, OS version, user and computer name, and other environmental details as shown in this intercepted communication.

The malware’s sophisticated multi-layered approach allows it to maintain persistence while downloading additional modules based on the attacker’s objectives.

This modular architecture makes PureRAT particularly dangerous, as it can adapt its capabilities to the specific target environment and security posture.

The attackers behind this campaign continue to refine their techniques, making this an ongoing threat to organizations that must maintain vigilant email security practices and user awareness training to prevent initial infection.

Equip your SOC team with deep threat analysis for faster response -> Get Extra 𝗦𝗮𝗻𝗱𝗯𝗼𝘅 𝗹𝗶𝗰𝗲𝗻𝘀𝗲𝘀 for Free

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

4 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

4 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

5 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

6 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

6 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

7 hours ago