#PureLog
Copyright Complaint Lures Linked to New PureLog Stealer Credential Theft Wave gbhackers.com/new-purelog-...
Copyright Complaint Lures Linked to New PureLog Stealer Credential Theft Wave
Threat actors are actively distributing the PureLog Stealer through a sophisticated, multi-stage attack campaign disguised as legal copyright violation notices.
gbhackers.com
March 22, 2026 at 8:46 AM
Copyright Lures Mask a Multi‑Stage PureLog Stealer Attack on Key Industries www.trendmicro.com/en_us/resear...
Copyright Lures Mask a Multi‑Stage PureLog Stealer Attack on Key Industries
We look into a stealthy multi‑stage attack campaign that delivers PureLog Stealer entirely in memory using encrypted, fileless techniques.
www.trendmicro.com
March 20, 2026 at 10:12 PM
Fileless Malware Abuses Google Blogspot to Deploy Infostealer in Memory
Veil#Drop Uses Google Blogspot to Deploy PureLog Stealer
Securonix said the Veil#Drop campaign abuses Google Blogspot to deliver PureLog Stealer in memory
www.infosecurity-magazine.com
July 7, 2026 at 1:42 AM
著作権侵害を装った巧妙な手口で主要産業を標的とした多段階のPureLog窃盗攻撃を隠蔽
#CybersecurityNews
www.trendmicro.com/en_us/resear...
Copyright Lures Mask a Multi‑Stage PureLog Stealer Attack on Key Industries
We look into a stealthy multi‑stage attack campaign that delivers PureLog Stealer entirely in memory using encrypted, fileless techniques.
www.trendmicro.com
March 26, 2026 at 3:12 PM
Nope, I think Steve posted the wrong link. SwissPost cyber security group did a deepdive on PURElogs: www.swisspost-cybersecurity.ch/news/purelog...
Don't Judge a PNG by Its Header: PURELOGS Infostealer Analysis
Swiss Post Cybersecurity traced a suspicious JavaScript file to a stealthy PURELOGS stealer that hides its payload within a PNG file.
www.swisspost-cybersecurity.ch
January 26, 2026 at 5:26 PM
Swiss Post Cybersecurity researcher Louis Schürmann describes the complete attack chain in a PURELOGS stealer campaign, from the initial use of legitimate infrastructure to the final data exfiltration. www.swisspost-cybersecurity.ch/news/purelog...
January 20, 2026 at 11:25 AM
PureLog Stealer Campaign: Fileless Malware Disguised as Legal Notices Targets Critical Infrastructure

Introduction: A New Layer of Deception in Cybercrime Cyber threats are no longer just about malicious downloads or suspicious attachments. Attackers are evolving, blending social engineering with…
PureLog Stealer Campaign: Fileless Malware Disguised as Legal Notices Targets Critical Infrastructure
Introduction: A New Layer of Deception in Cybercrime Cyber threats are no longer just about malicious downloads or suspicious attachments. Attackers are evolving, blending social engineering with highly advanced technical execution. The latest campaign distributing the PureLog Stealer demonstrates this shift clearly. By disguising malware as localized copyright violation notices, threat actors are not only exploiting fear and urgency but also bypassing traditional detection systems with alarming precision.
undercodenews.com
March 21, 2026 at 4:33 AM
Securonix researchers analyse a multi-stage malware delivery framework that uses social engineering, compromised websites, malicious JavaScript launchers, PowerShell download cradles & trusted cloud-hosted infra to deploy PureLog Stealer entirely in memory. www.securonix.com/blog/veildro...
July 2, 2026 at 9:13 AM
Securonix details Veil#Drop, a multi-stage attack chain using compromised sites, JavaScript, and PowerShell to deliver payloads from Blogspot, ending with PureLog Stealer data theft. #VeilDrop #PureLogStealer #Blogspot
Blogspot-Hosted Payloads Delivered in ‘Veil#Drop’ Attacks
Securonix uncovered Veil#Drop, a multi-stage malware delivery framework that uses compromised websites, JavaScript launchers, and PowerShell download cradles hosted on Blogspot to deliver malware. The chain ultimately infects victims with PureLog Stealer, which harvests credentials, cookies, tokens, browser history, and other sensitive data from multiple browsers and applications. #VeilDrop #PureLogStealer #Blogspot...
www.hendryadrian.com
July 6, 2026 at 10:45 PM
Veil#Drop delivers PureLog Stealer via compromised sites and social engineering using JavaScript, PowerShell, Blogspot payloads, obfuscation, and LOLBIN evasion.
Save What Matters
Curate Feeds | Make Collections | Customize Email Briefs
briefly.co
July 6, 2026 at 7:42 PM
A variant of the PureLogs infostealer malware has been distributed through purchase-order-themed phishing emails that use a malicious JavaScript file to launch a multi-stage infection chain on Windows systems.

www.infosecurity-magazine.com/news/purelog...
PureLogs Variant Steals Data via Purchase Order Lures
FortiGuard Labs detailed a PureLogs campaign using JavaScript, PowerShell and process hollowing
www.infosecurity-magazine.com
May 28, 2026 at 4:55 AM
Útočníci šíří malware PureLog Stealer prostřednictvím vícefázové kampaně maskované jako oznámení o porušení autorských práv
Copyright Complaint Lures Linked to New PureLog Stealer Credential Theft Wave
Threat actors are actively distributing the PureLog Stealer through a sophisticated, multi-stage attack campaign disguised as legal copyright violation notices.
gbhackers.com
March 22, 2026 at 10:58 AM
Threat actors exploited Anthropic’s Claude Code npm packaging error to distribute Vidar, GhostSocks, and PureLog stealers via trojanized archives and Rust droppers. Detection and mitigation efforts ongoing. #AnthropicRisk #GitHubThreat
Claude Code Packaging Error Remains a Lure in an Active Campaign: What Defenders Should Do
Threat actors exploited Anthropic’s Claude Code npm release packaging error to host malicious GitHub releases that distributed Vidar, GhostSocks, and PureLog Stealer via trojanized archives and a Rust-compiled dropper. TrendAI Research tracked the campaign to the repository github[.]com/leaked-claude-code/leaked-claude-code (GitHub account idbzoomh1), published detection guidance, IOCs, and immediate mitigation steps including endpoint...
www.hendryadrian.com
April 8, 2026 at 12:00 AM
A multi-stage PureLog Stealer campaign targets key industries using localized copyright phishing lures and fileless execution via Python and .NET loaders on Windows systems, with AMSI bypass and memory-only payloads. #PureLog #FilelessAttack
Copyright Lures Mask a Multi‑Stage PureLog Stealer Attack on Key Industries
A targeted, multi‑stage campaign delivers PureLog Stealer using localized phishing lures and an evasive, encrypted delivery chain that extracts and executes payloads entirely in memory. The attack employs fileless techniques including a Python loader, dual .NET loaders, AMSI bypass, remote key retrieval, and C2 exfiltration, impacting organizations running Windows in healthcare,...
www.hendryadrian.com
March 20, 2026 at 10:00 AM
Hackers Abuse Blogspot and PowerShell Download Cradles to Deploy PureLog Steale
Hackers Abuse Blogspot and PowerShell Download Cradles to Deploy PureLog Steale
Hackers have found a clever way to sneak data-stealing malware onto victims’ computers by hiding their tracks inside a trusted platform, Google Blogspot. Researchers recently uncovered a campaign abusing this blogging service alongside native Windows tools to quietly install an information stealer known as PureLog Stealer. The attack begins with something deceptively simple. A file named transcript.pdf.js looks like an ordinary PDF at first glance, but Windows treats it very differently behind the scenes. Since Windows often hides file extensions by default, victims see only transcript.pdf and have little reason to suspect anything is wrong. Once opened, the file runs through Windows Script Host and immediately launches PowerShell with security checks turned off. From there, PowerShell reaches out to attacker-controlled Blogspot pages to fetch the next stages, without saving a suspicious file to disk. Researchers from Securonix said in a report shared with Cyber Security News (CSN) that they identified and documented this framework, naming it Veil#Drop for how it conceals activity behind layers of encoding and legitimate looking web traffic. Hidden file extension masking transcript.pdf.js as a PDF in Windows Explorer (Source – Securonix) Their analysis traced the chain from the first click to the final theft of browser passwords and cryptocurrency wallet data. The campaign stands out because each step looks so ordinary. PowerShell commands, Blogspot visits, and trusted Microsoft utilities are things security teams see every day, which is why this approach slips past antivirus tools so easily. Hackers Abuse Blogspot and PowerShell Download Cradles The trick starts with a compromised website hosting the fake document file. Once a victim double clicks transcript.pdf.js, Windows Script Host quietly hands control to PowerShell, forcing a connection with execution policy checks bypassed entirely. PowerShell then uses a download cradle, fetching code directly from a Blogspot page and running it from memory. Nothing is written to the hard drive at this stage, so many file scanning tools never inspect it. PowerShell execution policy bypass scoped to the current process (Source – Securonix) The retrieved file, named phud.dudus.docx.pdf.olp.sys, deletes the original JavaScript launcher to erase evidence and shuts down background processes that might interfere later. It also decrypts a hidden payload using a repeating XOR key. That decrypted script builds a new Blogspot web address on the fly, adding random characters so each infection looks different. This makes it harder for defenders to block the campaign using a fixed list of bad domains. The newly fetched file, niple.docx.odp.pdf.sys, carries two large blocks of encoded numeric data. These decode into working dot NET programs, loaded directly into memory using reflection, meaning no executable ever touches the disk. If that approach fails, the malware falls back on trusted Microsoft signed tools such as InstallUtil, MSBuild, RegSvcs, and the C sharp compiler, blending in with activity that security software usually ignores. What PureLog Stealer Does Next Once active, PureLog Stealer harvests whatever valuable data it can find, including saved browser passwords, cookies, autofill entries, browsing history, and cryptocurrency wallet details. The stealer also gathers information about the infected system, giving attackers a clearer picture of what they compromised. This happens quietly, often without any visible sign that something is wrong. Because the chain runs from memory and avoids writing files, standard antivirus scans can easily miss it. Security teams are better served watching behavior, such as PowerShell reaching out to Blogspot or spawning tools it would not normally touch. The embedded XOR-encoded payload and its runtime decryption routine (Source – Securonix) Researchers recommend restricting which scripts Windows Script Host can run, especially where it serves no real business purpose. Turning on PowerShell logging and watching for policy bypass attempts can catch this activity early. Monitoring outbound connections to trusted cloud platforms for unusual patterns, rather than relying purely on domain reputation, gives defenders a better chance of spotting this abuse. Application control and least privilege further reduce the odds fallback techniques succeed. This framework shows a deliberate effort to slip past antivirus products and detection systems throughout the attack. Awareness remains one of the strongest defenses given how ordinary each step looks alone. Employees should stay cautious about unexpected downloads bearing unusual double extensions like those seen throughout this campaign. Indicators of Compromise (IoCs):- Type Indicator Description Filename transcript.pdf.js Initial JavaScript launcher disguised as a PDF document  Filename phud.dudus.docx.pdf.olp.sys Second-stage PowerShell loader retrieved from Blogspot  Filename niple.docx.odp.pdf.sys Third-stage loader containing encoded PureLog Stealer assemblies  Domain htlwub00klocate[.]blogspot[.]com Blogspot domain used to stage the second-stage payload  Domain cpyzaramay26[.]blogspot[.]com Blogspot domain used to stage the third-stage payload  URL hxxps://htlwub00klocate[.]blogspot[.]com/phud.dudus.docx.pdf.olp.sys URL delivering the second-stage PowerShell loader  URL hxxps://cpyzaramay26[.]blogspot[.]com/niple.docx.odp.pdf.sys URL delivering the final-stage loader for PureLog Stealer  Note:   IP addresses and domains are intentionally defanged (e.g.,  [.] ) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM .  Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. ->  Integrate ANY.RUN With Your SOC  Now . The post Hackers Abuse Blogspot and PowerShell Download Cradles to Deploy PureLog Steale appeared first on Cyber Security News .
cybersecuritynews.com
July 3, 2026 at 12:36 PM
Copyright-Themed Lures Deliver Multi-Stage PureLog Stealer in New Credential Theft Campaign
Copyright-Themed Lures Deliver Multi-Stage PureLog Stealer in New Credential Theft Campaign
A new malware campaign is targeting organizations across healthcare, government, education, and hospitality sectors using cleverly disguised copyright violation notices to deliver PureLog Stealer, a powerful information-stealing malware. The campaign, first analyzed in March 2026, tricks victims into executing a malicious file that looks like a legitimate legal document. Once opened, the file sets off a quiet but complex chain of events that ends with sensitive data being stolen from the victim’s machine. PureLog Stealer is an infostealer known for harvesting browser credentials, cryptocurrency wallet data, browser extension data, and general system information. It is classified as a low-cost, easy-to-use tool, which means even less-skilled threat actors can deploy it. The campaign uses phishing emails with malicious download links — rather than direct attachments — to deliver language-specific lures, with German-language variants targeting Germany and English-language versions targeting Canada and other regions. Trend Micro researchers identified that the campaign does not rely on software vulnerabilities or exploits. Instead, it depends entirely on social engineering, convincing users to manually run a file disguised as a copyright complaint. The malicious executable carries names like  “Documentation on Intellectual Property Rights Violations.exe,”  making it appear genuine to an unsuspecting recipient. This approach makes the campaign particularly dangerous because standard patch management alone cannot stop it. The campaign has been most active against organizations in Germany and Canada, with additional victims observed in the United States and Australia. Industries targeted include healthcare, government, hospitality, and education — sectors that often deal with legal notices and compliance documents, making the copyright lure format highly believable. The selective targeting and localized delivery suggest a structured operation rather than a random mass spam campaign . What makes this threat stand out is the level of technical sophistication woven throughout its delivery chain. The malware uses encrypted payloads, remote decryption key retrieval, and fully in-memory execution — leaving very little forensic trace on compromised machines. Endpoint detection tools that rely on file creation monitoring would find almost nothing to flag. Inside the Multi-Stage Infection Chain Once the victim executes the malicious lure, a command interpreter launches silently in the background. To keep the user occupied, a harmless-looking decoy PDF immediately opens on screen. Infection chain of the attack (Source – Trend Micro) Meanwhile, the malware contacts attacker-controlled infrastructure to download an encrypted archive disguised as a PDF file named  invoice.pdf . Rather than embedding the decryption password inside the malware itself, the attackers retrieve it remotely from a separate server endpoint at runtime. This design makes offline analysis nearly impossible and allows the attacker to control or cancel each infection remotely. A renamed WinRAR executable — disguised as a PNG image file — then uses that retrieved password to extract the real payload.  Malicious lure download from unknown source (Source – Trend Micro) The extracted content includes a renamed Python interpreter called  svchost.exe  and a heavily obfuscated Python script named  instructions.pdf . The script first bypasses Windows Defender’s Antimalware Scan Interface by patching memory directly, preventing the system from scanning what follows. Python code patching AMSI in memory (Source – Trend Micro) It then establishes registry persistence under  HKCU\Run\SystemSettings , ensuring the malware restarts automatically on every user login.  The script also takes a full-screen screenshot, collects the machine hostname, username, and installed antivirus product names, then sends all of it to the command-and-control server via an HTTPS POST request. Finally, two identical .NET loader files decrypt and load PureLog Stealer directly into memory, leaving no files on disk for antivirus tools to find. Infection chain for PureLog Stealer (Source – Trend Micro) Organizations should train employees to treat unexpected emails about copyright violations with caution, especially those containing download links. Security teams should monitor registry Run keys for unusual entries, watch for Python or WinRAR processes executing from non-standard directory paths, and block outbound connections to known malicious domains . Behavioral detection tools and network telemetry are essential, as traditional signature-based antivirus may miss this campaign entirely due to its fileless execution design. Follow us on  Google News ,  LinkedIn , and  X  to Get More Instant Updates ,  Set CSN as a Preferred Source in  Google . The post Copyright-Themed Lures Deliver Multi-Stage PureLog Stealer in New Credential Theft Campaign appeared first on Cyber Security News .
cybersecuritynews.com
March 23, 2026 at 7:26 AM
Invisible Threat: Fileless VeilDrop Malware Exploits Google Blogspot to Deploy PureLog Stealer Directly Into Memory + Video

Introduction: A New Generation of Stealth Malware Is Changing the Cybersecurity Battlefield Cybercriminals are constantly evolving, but some attacks stand out because they…
Invisible Threat: Fileless VeilDrop Malware Exploits Google Blogspot to Deploy PureLog Stealer Directly Into Memory + Video
Introduction: A New Generation of Stealth Malware Is Changing the Cybersecurity Battlefield Cybercriminals are constantly evolving, but some attacks stand out because they challenge the very foundations of traditional security defenses. Security researchers have now uncovered an advanced fileless malware framework known as VeilDrop, a sophisticated campaign that abuses Google's Blogspot platform to secretly distribute the PureLog Stealer without leaving traditional files on infected systems.
undercodenews.com
July 1, 2026 at 2:44 PM
Invisible Cyber Threat: How PureLog Stealer Is Silently Infiltrating Global Industries

Introduction: A New Breed of Silent Cyber Attacks Cybersecurity threats are no longer loud, obvious, or easy to detect. Today’s attackers operate in the shadows, using highly sophisticated techniques that leave…
Invisible Cyber Threat: How PureLog Stealer Is Silently Infiltrating Global Industries
Introduction: A New Breed of Silent Cyber Attacks Cybersecurity threats are no longer loud, obvious, or easy to detect. Today’s attackers operate in the shadows, using highly sophisticated techniques that leave little to no trace behind. One of the latest examples is the PureLog Stealer campaign, a multi-stage cyberattack designed to infiltrate critical industries through deceptive phishing tactics and advanced fileless execution.
undercodenews.com
March 20, 2026 at 10:25 AM
Blogspot-Hosted PowerShell Loader Delivers PureLog Stealer Through XOR-Encoded In-Memory .NET Payloads https://packetstorm.news/news/view/42248 #news
July 3, 2026 at 6:40 PM
Copyright Lures Mask A Multi-Stage PureLog Stealer Attack On Key Industries https://packetstorm.news/news/view/40875 #news
March 23, 2026 at 9:37 PM
Hackers abuse Blogspot and PowerShell Download Cradles to deploy PureLog Steale:

cybersecuritynews.com/hackers-abus...
July 3, 2026 at 1:54 PM
Copyright-Themed Lures deliver(s) Multi-Stage PureLog Stealer in new Credential Theft Campaign:

cybersecuritynews.com/copyright-th...
March 23, 2026 at 7:50 AM