logo

Hackers Abuse Blogspot and PowerShell Download Cradles to Deploy PureLog Steale

ID: 71f9b864-ff1b-57d8-9f9a-355812d6e4da

STIX ID: report--71f9b864-ff1b-57d8-9f9a-355812d6e4da

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-07-03

Date Updated: 2026-07-03

Author: Tushar Subhra Dutta

...
...

Researchers uncovered a Veil#Drop campaign that hides an information-stealer (PureLog Stealer) delivery chain inside Google Blogspot pages: victims open a file named like transcript.pdf.js which launches PowerShell with execution policy bypass, fetches staged payloads from Blogspot, performs in-memory decryption and reflective loading of .NET assemblies (avoiding disk writes), and resorts to signed Microsoft tools if needed; the stealer exfiltrates saved browser credentials, cookies, autofill data, browsing history, and cryptocurrency wallet information. The report includes filenames, Blogspot domains and URLs as IoCs and recommends restricting Windows Script Host, enabling PowerShell logging, monitoring outbound traffic to trusted cloud platforms for anomalous patterns, and applying application control and least privilege.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.