216.73.216.6

New Loader Executing TorNet and PureHVNC

· Published 31/10/2025 09:31 · Modified 31/10/2025 11:22

Export JSON

Essential information

Published
31/10/2025 09:31
Modified
31/10/2025 11:22
Tags
2025-10-31 code injection loader murmurhash2 purehvnc tornet
Related entities
4 techniques (mitre), 2 malware

Description

A new malware discovered in May 2025 executes two malware families: and . The uses API hashing with and implements persistence through registry modifications. It decrypts and decompresses payloads using AES-128-ECB and LZMA, then injects them into a suspended jsc.exe process. , a downloader malware, communicates via TOR network, while is a commercial RAT allowing remote access. Both malware use Protocol Buffers for configuration deserialization. The 's unique characteristics include its dual payload execution and API hashing implementation, indicating potential future attack techniques.

External references