Close Menu
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
What's Hot

Inside UK’s Premier League crypto warning and what comes next

June 4, 2026

3D Systems Announces Pricing of $50 Million Upsized Public Offering

June 4, 2026

why big banks hesitate in front of blockchain

June 4, 2026
Facebook X (Twitter) Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
Facebook X (Twitter) Instagram
CryptoPulseDaily.com
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
CryptoPulseDaily.com
Home»Security and Privacy»Accounting Firm Targeted by Malware Campaign Using New Crypter
Accounting Firm Targeted by Malware Campaign Using New Crypter
Security and Privacy

Accounting Firm Targeted by Malware Campaign Using New Crypter

July 22, 20251 Comment3 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

A cyber-attack on a US-based accounting firm in May 2025 has been observed delivering the PureRAT remote access Trojan using a sophisticated crypter called Ghost Crypt.

According to researchers at eSentire’s Threat Response Unit (TRU), the campaign involved social engineering, advanced obfuscation techniques and a multi-stage malware delivery process.

PureRAT Delivered Through Ghost Crypt and Social Engineering

The attacker, posing as a new client, sent a malicious PDF linking to a Zoho WorkDrive folder. The folder contained a ZIP archive disguised as tax documentation. Inside was a file with a deceptive double extension (.pdf.exe) and a renamed DLL. When executed, the bundled crypter decrypted and injected PureRAT into the legitimate Windows binary csc.exe.

Ghost Crypt, advertised on Hackforums since April 2025, claims to bypass major antivirus solutions and supports the sideloading of both EXE and DLL files. It uses a custom variant of the ChaCha20 algorithm and employs an injection method called “Process Hypnosis” to deliver payloads undetected.

The attacker further ensured persistence by adding a registry key entry and copying the DLL to the user’s documents folder.

Ghost Crypt Features and Malware Behavior

Ghost Crypt promotes several features:

  • Bypasses Windows Defender and cloud-based detection

  • Compatible with Windows 11 24H2+

  • Includes customizable icons and DLL stub sizing

  • Offers a 3-day survival guarantee with free recrypts

  • Supports malware families like LummaC2, Rhadmanthys, and XWorm

Read more on Windows malware injection techniques: Winos4.0 Malware Found in Game Apps, Targets Windows Users

The attack used legitimate software – hpreader.exe by Haihaisoft – for DLL sideloading. This, eSentire warned, highlights the challenge of distinguishing benign tools from malicious loaders.

The injected PureRAT payload communicates with command-and control (C2) servers, collecting user data, system details and searching for crypto wallets and desktop apps like Ledger Live and Exodus.

See also  Woman To Serve About Seven Years Behind Bars for Laundering Bitcoin Proceeds of $6,400,000,000 Fraud: Report

PureRAT Evolves as Main Offering from PureCoder

PureRAT has replaced PureHVNC as the flagship product from underground seller PureCoder.

The malware is packed using .NET obfuscators and compressed with encryption layers including AES-256 and GZIP. It loads DLLs using direct memory injection instead of traditional execution techniques.

Upon successful installation, the malware scans browsers for crypto wallet extensions and uses SetThreadExecutionState API calls to prevent the system from entering sleep mode. It then transmits collected data and awaits further instructions from its operators.

eSentire warned organizations to remain vigilant against urgent requests from unknown sources, particularly involving cloud storage links. They also advised enabling file extension visibility, using EDR tools and verifying the legitimacy of unexpected communications.

Source link

Accounting campaign Crypter firm Malware Targeted
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

New DeFi entrant widens field of crypto political campaign funds as elections loom

June 3, 2026

Infosecurity Europe: AI-Powered Cybercrime Tools Surge on Dark Web

June 3, 2026

Digital asset firm Keyrock plans to acquire BlockFills out of bankruptcy

June 2, 2026

U.S. says it seized about $1 billion in Iranian crypto as pressure campaign expands

May 31, 2026
View 1 Comment

1 Comment

  1. Nellie3287 on July 22, 2025 7:36 am

    https://shorturl.fm/EXOqa

    Reply
Leave A Reply Cancel Reply

Top Posts

SBF’s lawyers want to quiz jurors on crypto, altruism and ADHD

September 14, 2023

Nike Trips Up .SWOOSH Launch While Bitcoin NFTs Soar

May 28, 2023

Sanctioned nations are secretly mining Bitcoin and the clues are in the hash rate

August 1, 2025

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

Our mission is to develop a community of people who try to make financially sound decisions. The website strives to educate individuals in making wise choices about Crypto, ICOs, Web3, Blockchain and more.

We're social. Connect with us:

Facebook X (Twitter) Instagram Pinterest YouTube
Top Insights

Inside UK’s Premier League crypto warning and what comes next

June 4, 2026

3D Systems Announces Pricing of $50 Million Upsized Public Offering

June 4, 2026

why big banks hesitate in front of blockchain

June 4, 2026
Get Informed

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

  • Contact
  • Privacy Policy
  • Terms & Conditions
© 2026 Crypto Pulse Daily - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.

Cleantalk Pixel
  • bitcoinBitcoin(BTC)$64,014.00-4.33%
  • ethereumEthereum(ETH)$1,794.68-3.75%
  • tetherTether(USDT)$1.000.03%
  • binancecoinBNB(BNB)$612.19-4.31%
  • usd-coinUSDC(USDC)$1.000.00%
  • rippleXRP(XRP)$1.20-1.89%
  • solanaSolana(SOL)$70.61-4.84%
  • tronTRON(TRX)$0.3324960.31%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.00-3.33%
  • HyperliquidHyperliquid(HYPE)$73.010.45%