logo

PawsRunner Loader Uses Steganography To Deploy PureLogs Infostealer

ID: 2a315d95-3f10-5db2-8ec4-d96b8ccc0492

STIX ID: report--2a315d95-3f10-5db2-8ec4-d96b8ccc0492

Feed Name: Cyber Press

Threat Score
75/100

Date Published: 2026-05-18

Date Updated: 2026-05-18

Author: Varshini

...
...

FortiGuard Labs reported a phishing campaign in which attackers send a TXZ attachment that launches a fileless .NET loader (PawsRunner) via hidden PowerShell environment variables; PawsRunner retrieves PNG “cat” images containing encrypted payloads via steganography to deploy the PureLogs infostealer, which harvests browser credentials, password manager data, recovery phrases/private keys, and specific crypto wallet extension data (several extension IDs are provided).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.