Contact

Ghost Crypt Powers PureRAT with Hypnosis

NetmanageIT OpenCTI - opencti.netmanageit.com

Ghost Crypt Powers PureRAT with Hypnosis



SUMMARY :

In May 2025, eSentire's Threat Response Unit (TRU) uncovered a targeted attack on a U.S. accounting firm. The attackers used a newly advertised crypter service, Ghost Crypt, to sideload and obfuscate a DLL into a legitimate Windows component (csc.exe), deploying PureRAT, a Remote Access Trojan that surged in 2025

OPENCTI LABELS :

remote access trojan,purerat,ghostcrypt


Open in NetmanageIT OpenCTI Public Instance with below link!


Use public read only username and password on login page.

NOTE : Use Public READ only user credentials on login page banner.


Ghost Crypt Powers PureRAT with Hypnosis