Copyright-Themed Lures Deliver Multi-Stage PureLog Stealer in New Credential Theft Campaign
ID: dfd0eea3-f7aa-5442-93ef-2e7e4509e0fa
STIX ID: report--dfd0eea3-f7aa-5442-93ef-2e7e4509e0fa
Feed Name: cybersecurityNews.com
A targeted phishing campaign uses fake copyright violation notices and language-specific lures to trick victims into downloading and executing a malicious executable that ultimately deploys PureLog Stealer; the multi-stage attack employs encrypted payloads with runtime decryption, a renamed Python interpreter and WinRAR, AMSI patching to evade scans, registry persistence (HKCU\Run\SystemSettings), and in-memory .NET loaders to exfiltrate browser credentials, crypto wallet data, and system information from organizations in healthcare, government, education, and hospitality across multiple countries.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
