PURELOGS Payload Hidden in Weaponized PNG Images Used in Stealth Attacks
ID: 06b94961-8825-5994-9d37-ac25cfe78d5f
STIX ID: report--06b94961-8825-5994-9d37-ac25cfe78d5f
Feed Name: GBHackers
This report describes a multi-stage PURELOGS infostealer campaign in which a phishing email delivers an obfuscated JScript dropper that launches a hidden PowerShell process to download a PNG polyglot from archive.org containing a Base64 payload; the payload is decoded in memory, loaded via .NET reflection, and injected into a legitimate CasPol.exe process using RunPE, enabling credential and cryptocurrency wallet theft. The analysis details fileless execution, VM/sandbox detection, targeted applications (Chromium browsers, 30+ wallets, 70+ Web3 extensions), and includes multiple IOCs (SHA256 hashes, URLs, IP addresses, and C2 endpoint).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
