#PureLogs
Fake complaint emails drop PureRAT/PureLogs - one loader BYOVDs a Lenovo driver to kill your EDR. https://intel.threadlinqs.com/threat/TL-2026-2652 #ThreatIntel #PureRAT #PureCoder #PureLogs
September 25, 2026 at 12:31 PM
PureRAT/PureLogs phish hits Japan/Korea via a wall of loaders and a BYOVD EDR-kill - one stealer behind it all. https://intel.threadlinqs.com/threat/TL-2026-2647 #ThreatIntel #PureRAT #PureLogs #Korean
September 25, 2026 at 5:07 AM
💧 Dropper connects to legitimate website
📄 Fake PDF is downloaded over HTTPS
💾 Fake PDF is decrypted to a #PureLogs DLL
⚙️ InstallUtil.exe or RegAsm.exe is started
💉 PureLogs DLL is injected into the running process
👾 PureLogs connects to C2 server
netresec.com?b=257eead
PureLogs Forensics
I analyzed some PureLogs malware infections this morning and found some interesting behavior and artifacts that I want to share. PureLogs infections sometimes start with a dropper/downloader that retr...
netresec.com
July 2, 2025 at 12:15 PM
Nope, I think Steve posted the wrong link. SwissPost cyber security group did a deepdive on PURElogs: www.swisspost-cybersecurity.ch/news/purelog...
Don't Judge a PNG by Its Header: PURELOGS Infostealer Analysis
Swiss Post Cybersecurity traced a suspicious JavaScript file to a stealthy PURELOGS stealer that hides its payload within a PNG file.
www.swisspost-cybersecurity.ch
January 26, 2026 at 5:26 PM
📢🚨🎣 Fake purchase order emails are spreading fileless #PureLogs malware through malicious RAR archives, targeting Windows users and stealing browser credentials, crypto wallet data, VPN logins, Discord tokens, and more.

Read: hackread.com/purchase-ema...

#Cybersecurity #Malware #Phishing #Windows
Fake Purchase Order Emails Spread Fileless PureLogs Malware via RAR Archives
Hackers are using fake purchase order emails and process hollowing to deploy fileless PureLogs malware to steal Windows users' browser, crypto, and Discord data.
hackread.com
June 1, 2026 at 11:01 AM
Dissecting a new malspam chain delivering Purelogs infostealer securityaffairs.com/185066/cyber...
Dissecting a new malspam chain delivering Purelogs infostealer
The AISI Research Center's Cybersecurity Observatory publishes the report "Dissecting a new malspam chain delivering Purelogs infostealer"
securityaffairs.com
November 30, 2025 at 11:12 AM
FortiGuard Labs found a phishing campaign using a fake purchase order, malicious RAR, and JavaScript to deploy PureLogs via PowerShell and process hollowing, stealing browser, Discord, wallet, and app data. #PureLogs #FortiGuardLabs #Windows
Phishing Campaign Deploys JavaScript-Driven PureLogs Variant to Steal Sensitive Data
FortiGuard Labs identified a phishing campaign that delivers a PureLogs variant through a fake purchase-order email carrying a malicious RAR archive and JavaScript file. The attack chain uses PowerShell, process hollowing, and a downloader to load an in-memory plugin that steals browser, Discord, crypto wallet, and application data from Windows systems. #PureLogs #FortiGuardLabs #MsBuild.exe #Discord #MicrosoftEdge #FileZilla
www.hendryadrian.com
June 5, 2026 at 2:45 AM
ตรวจพบมัลแวร์ PureLogs เล็งเป้าโจมตีผู้ใช้งานเว็บเบราว์เซอร์ Chrome เพื่อขโมยข้อมูล
October 22, 2024 at 12:32 PM
Interesting deep dive on how the PureLogs infostealer operates by Tobias Bieniek

blog.rust-lang.org/2026/01/21/c...
crates.io: development update | Rust Blog
Empowering everyone to build reliable and efficient software.
blog.rust-lang.org
January 26, 2026 at 10:07 AM
Swiss Post Cybersecurity researcher Louis Schürmann describes the complete attack chain in a PURELOGS stealer campaign, from the initial use of legitimate infrastructure to the final data exfiltration. www.swisspost-cybersecurity.ch/news/purelog...
January 20, 2026 at 11:25 AM
zgRAT is a confusing catch-all label: both #PureLogs and #PureRAT commonly trigger "zgRAT" detections. Please don't label malware as #zgRAT.
netresec.com?b=267e877
PureLogs, PureRAT and misleading zgRAT
Please stop classifying malware as zgRAT. That malware label is confusing. As far as I know, there isnt a proper definition of what zgRAT actually is. Some claim that zgRAT is the same malware family ...
netresec.com
July 27, 2026 at 4:18 PM
Malspam remains a key threat, using weaponized docs and complex exploit chains. As @Exprivia_CY notes, “40% of #cybercrime incidents use AI”. Recent campaigns include the Purelogs infostealer, hitting victims we, #Italy included . Read dimanec.unipegaso.it/wp-content/u... via #securityaffairs
dimanec.unipegaso.it
November 26, 2025 at 11:10 AM
The latest update for #BlueVoyant includes "From GrimResource to PureLogs Stealer: Dissecting a Recent Attack" and "Maximizing Your Security Investment with the Microsoft #Azure Consumption Commitment (MACC)".

#Cybersecurity #MDR #ThreatIntelligence https://opsmtrs.com/47iWeco
BlueVoyant
A comprehensive security operations platform empowered by AI to enable uninterrupted protection against potential threats.
opsmtrs.com
September 19, 2025 at 11:50 PM
📢 Analyse technique de la campagne PureLogs Stealer 2026 : chaîne d'infection multi-stages

ITrust (https://www.itrust.fr), publiée le 2 septembre 2026. L'analyse fait suite à une alerte EDR déclenchée mi-juillet 2026 chez un…

🟢 vérification factuelle haute
#PureLogs #PureLogsStealer #Cyberveille
Analyse technique de la campagne PureLogs Stealer 2026 : chaîne d'infection multi-stages
ITrust (https://www.itrust.fr), publiée le 2 septembre 2026. L'analyse fait suite à une alerte EDR déclenchée mi-juillet 2026 chez un client, bloquant une communication réseau issue d'une exécution PowerShell. Le CERT ITrust a rétro-ingénié la chaîne complète malgré le blocage de l'attaque.
cyberveille.ch
September 7, 2026 at 10:30 PM
📢 [Analyse] Rétro-ingénierie d’une récente campagne PureLogs Stealer

Parmi les attaques quotidiennes qui sont observées par les analystes SOC durant leur supervision, les malwares de type stealer ont une place de choix.

#Malware #Cyberveille
[Analyse] Rétro-ingénierie d’une récente campagne PureLogs Stealer
Parmi les attaques quotidiennes qui sont observées par les analystes SOC durant leur supervision, les malwares de type stealer ont une place de choix.
www.itrust.fr
September 2, 2026 at 9:30 AM
@james_inthe_box That's interesting. Headless Chrome and Edge instances with `--no-sandbox` could be a decent artifact to hunt for, right? Here's a writeup touching on this:
https://blog.deception.pro/blog/cpuz-trojan-stxrat-purelogs-data-exfil-april-2026
August 5, 2026 at 2:49 PM
Google Safe Browsing overcorrected post-VEIL#DROP - falsely locking Blogger blogs as malware. https://intel.threadlinqs.com/threat/TL-2026-1890 #ThreatIntel #PureLogs #Blogger #VEILDROP
August 5, 2026 at 3:25 PM
@james_inthe_box Thank you for sharing! The #purelogs C2 server seems to be on 2.27.62.123:4449
Turns out JoeSandbox has history for that C2 server since at least 2026-04-08.
https://www.joesandbox.com/analysis/search?ioc-public-ip=2.27.62.123
August 3, 2026 at 12:44 PM
Handful of IOC's for those .js #purelogs #stealer #malspams:

https://app.any.run/tasks/43e561e4-707a-4189-8b4c-d4795b2451a6

Exfil port is 4449
Calls hidden Edge
Calls hidden Chrome
July 31, 2026 at 12:28 PM