Security researchers at eSentire have identified a sophisticated malware tool called Pure Crypter that employs multiple evasion techniques to bypass the enhanced security features introduced in Windows 11 build 26100 (24H2). This advanced crypter is being used as a malware delivery platform, enabling cybercriminals to deploy payloads such as ransomware, information stealers, and remote access trojans. The tool has been updated specifically to counter new defenses in Windows 11, including advanced memory protection and process injection safeguards. Pure Crypter stands out due to its ability to adapt to modern OS protections by using complex anti-analysis tactics such as AMSI bypassing, DLL unhooking, and customized process injection. It even performs a system check to identify if the target machine runs Windows 11 24H2, and, if so, patches the NtManageHotPatch API in memory to re-enable its RunPE (process hollowing) capabilities. This highlights how rapidly threat actors are evolving to outpace system defenses, presenting a serious challenge for endpoint protection platforms and traditional behavioral analysis tools. ?Organizations should immediately review endpoint protection policies and ensure that behavioral analysis tools are updated to detect memory patching and unauthorized system API modification. Network segmentation, strict application whitelisting, and monitoring of registry key modifications can further reduce exposure. Patching systems regularly and providing security awareness training can help reduce the risk of initial infection vectors, such as phishing or malicious downloads.
Cornwell Quality Tools, a prominent supplier of automotive and industrial tools, has confirmed a significant data breach that exposed the sensitive personal information of 103,782 ...
A critical security vulnerability, CVE-2025-10127, has been discovered in the Daikin Security Gateway. The flaw is a serious industrial control systems threat, especially in the en...
On September 9, 2025, Microsoft reported four significant security vulnerabilities in the Windows Defender Firewall Service CVE-2025-53808, CVE-2025-54104, CVE-2025-54109, and CVE-...