Hackers Hide PureLogs Infostealer in PawsRunner Loader
ID: 1f395d85-582b-5994-a25e-70481f790c5a
STIX ID: report--1f395d85-582b-5994-a25e-70481f790c5a
Feed Name: GBHackers
FortiGuard-investigated phishing campaign delivers a .NET loader called PawsRunner (disguised with cat icons) via TXZ attachments and JavaScript-driven PowerShell; PawsRunner prioritizes PNG responses and extracts encrypted payloads hidden in PNG chunks (steganography) to deploy the PureLogs infostealer, which harvests browsers, wallets, credentials and other sensitive data and exfiltrates it to C2 endpoints. Indicators (defanged IP, URL, multiple SHA256 hashes) and descriptions of persistence, RC4/RC4-like decryption, AES/TripleDES payload handling, in-memory execution, and evasion techniques are included.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
