logo

Copyright Lures Mask a Multi‑Stage PureLog Stealer Attack on Key Industries

ID: c455b218-f5cc-5593-8dc5-a97f30c41ca5

STIX ID: report--c455b218-f5cc-5593-8dc5-a97f30c41ca5

Feed Name: TrendAI Security Blog

Threat Score
75/100

Date Published: 2026-02-06

Date Updated: 2026-08-21

...
...

This report analyzes a targeted, multi-stage PureLog Stealer campaign that uses localized copyright‑lure executables and phishing/malvertising to deliver an encrypted payload masquerading as a PDF; attackers retrieve per-victim decryption keys remotely, use a renamed WinRAR for extraction, a Python loader (with AMSI bypass and in-memory .NET payload loading), and dual .NET loaders to execute the infostealer entirely in memory. Observed victims are primarily in healthcare and government across Germany, Canada, the US, and Australia, with active C2 infrastructure and multiple IOCs provided for detection and hunting.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.