PawsRunner Loader Uses Steganography To Deploy PureLogs Infostealer
ID: 2a315d95-3f10-5db2-8ec4-d96b8ccc0492
STIX ID: report--2a315d95-3f10-5db2-8ec4-d96b8ccc0492
Feed Name: Cyber Press
Threat Score
FortiGuard Labs reported a phishing campaign in which attackers send a TXZ attachment that launches a fileless .NET loader (PawsRunner) via hidden PowerShell environment variables; PawsRunner retrieves PNG “cat” images containing encrypted payloads via steganography to deploy the PureLogs infostealer, which harvests browser credentials, password manager data, recovery phrases/private keys, and specific crypto wallet extension data (several extension IDs are provided).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
