Pure Crypter Deploys Sophisticated Evasion Tactics to Evade Windows 11 24H2 Security Features

Pure Crypter has cemented its position as a prominent malware-as-a-service (MaaS) loader within the cybercriminal ecosystem, according to extensive research by eSentire’s Threat Response Unit (TRU).

Notably, Pure Crypter has been the tool of choice for deploying high-profile infostealers such as Lumma and Rhadamanthys, frequently exploiting the ClickFix initial access vector to compromise Windows-based environments.

The recent introduction of Windows 11 24H2 brought targeted mitigations against process hollowing, a common code injection technique leveraged by malware loaders.

Despite these efforts by Microsoft, Pure Crypter’s operators have rapidly adapted, employing in-memory patching of the NtManageHotPatch API to bypass newly enforced security boundaries.

Pure Crypter’s Advanced Loader

Pure Crypter’s prevalence and sophistication highlight its strategic role in the threat landscape.

The loader is actively marketed in cybercrime forums, with a tiered pricing model managed by the vendor “PureCoder” and distributed via the automated Telegram channel @ThePureBot.

Windows 11
 Pure Coder’s sales thread on HackForums[.]net

This infrastructure not only facilitates streamlined delivery of various “Pure” malware strains including Pure Miner, Pure RAT, Pure Logs Stealer, and Blue Loader but also automates the dissemination of payloads and real-time updates.

Subscribers are enticed with alleged “Fully Undetected” (FUD) payloads, as evidenced by scan analytics from avcheck[.]net.

However, eSentire’s comparative testing demonstrates a stark discrepancy between these advertised undetectability claims and reality: samples with supposedly zero detection yielded at least 20 detections when submitted to VirusTotal, challenging the credibility of crypter marketing and raising doubts about avcheck[.]net’s reliability as a stealth testing platform.

Operators of Pure Crypter take steps to maintain a veneer of legitimacy within illicit marketplaces, requiring buyers to agree to a Terms of Service (ToS) upon purchase.

Windows 11
Pure Crypter ToS agreement

This legalistic maneuver allows them to skirt explicit bans on malware sales in clear web forums while still providing highly weaponized software.

The loader’s graphical user interface (GUI) offers an accessible environment for both entry-level and advanced threat actors, allowing payload manipulation via local files or URLs.

Usage is regulated by operational quotas limiting the number of daily packing operations per subscription tier to prevent abuse while maintaining system availability.

Malware Marketplace Responds

Pure Crypter offers an array of configurable evasion features that can be selectively enabled, including Antimalware Scan Interface (AMSI) bypass, network connectivity disruption, execution delay, dynamic anti-VM and anti-debugging routines, as well as DLL unhooking techniques.

These options empower users to customize payloads for specific target environments, vastly complicating detection and incident response efforts.

Under the hood, Pure Crypter employs multiple anti-analysis and persistence mechanisms.

During the unpacking process, it decrypts and deserializes a Protobufs-based configuration file that governs all subsequent options and behaviors, such as mutex-based single-instance enforcement, debugger and virtualization checks (leveraging WMI and API calls), and parent process spoofing.

Notably, recent versions detect if a target is running Windows 11 24H2 or later, and if so, dynamically patch the NtManageHotPatch API to re-enable process hollowing, thus sidestepping Microsoft’s latest mitigations.

Additional modules allow the disabling of Defender via encoded PowerShell, adding Defender exclusions, executing arbitrary PowerShell commands, and establishing persistent footholds via registry, scheduled tasks, or startup scripts.

According to the Report, The loader also employs file inflation to circumvent AV/EDR backend upload limitations and features an “Anti File Delete” mechanism that leverages low-level file handle manipulation to resist forensic cleanup attempts.

Three primary payload execution methods are supported: .NET reflection loading, traditional RunPE (process hollowing), and direct shellcode injection using VirtualAlloc and CreateThread API calls.

These techniques ensure maximum flexibility for deploying a variety of malware types according to threat actor preferences.

To aid defenders, eSentire has released “PureCrypterPunisher”, an automated analysis tool that extracts Protobufs-based configs, decrypts embedded strings, and facilitates easier reverse engineering of Pure Crypter samples.

This technical deep-dive not only exposes Pure Crypter’s inner workings, distribution methods, and deceptive marketing practices but also illustrates the rapid iterative arms race between malware authors and Windows security innovators.

The loader’s persistent evolution and the agility of its operator community represent a clear and ongoing challenge for defenders, underscoring the critical need for continuous vigilance and adaptation in enterprise cybersecurity strategies.

Find this Story Interesting! Follow us on LinkedIn and X to Get More Instant Updates.

Mandvi
Mandvi
Mandvi is a Security Reporter covering data breaches, malware, cyberattacks, data leaks, and more at Cyber Press.

Trending News

Related Stories