Hackers Abuse Blogspot and PowerShell Download Cradles to Deploy PureLog Steale
ID: 71f9b864-ff1b-57d8-9f9a-355812d6e4da
STIX ID: report--71f9b864-ff1b-57d8-9f9a-355812d6e4da
Feed Name: cybersecurityNews.com
Researchers uncovered a Veil#Drop campaign that hides an information-stealer (PureLog Stealer) delivery chain inside Google Blogspot pages: victims open a file named like transcript.pdf.js which launches PowerShell with execution policy bypass, fetches staged payloads from Blogspot, performs in-memory decryption and reflective loading of .NET assemblies (avoiding disk writes), and resorts to signed Microsoft tools if needed; the stealer exfiltrates saved browser credentials, cookies, autofill data, browsing history, and cryptocurrency wallet information. The report includes filenames, Blogspot domains and URLs as IoCs and recommends restricting Windows Script Host, enabling PowerShell logging, monitoring outbound traffic to trusted cloud platforms for anomalous patterns, and applying application control and least privilege.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
