logo

PureLogs Malware Variant Abuses MSBuild.exe for Process Hollowing Attacks

ID: 86cd8afe-e188-584c-999c-843cc998839a

STIX ID: report--86cd8afe-e188-584c-999c-843cc998839a

Feed Name: Cyber Press

Threat Score
75/100

Date Published: 2026-05-28

Date Updated: 2026-05-28

Author: Varshini

...
...

A purchase-order-themed phishing campaign distributes an evasive, fileless variant of the PureLogs info-stealer that uses obfuscated JavaScript and PowerShell to execute in memory and abuse MSBuild.exe via process hollowing; the malware harvests system data, browser passwords and cryptocurrency wallets, encrypts stolen data with AES, and exfiltrates it to C2 infrastructure (examples in the report: https://77.83.39.211:8443, /ping, /plugin).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.