logo

Copyright Complaint Lures Linked to New PureLog Stealer Credential Theft Wave

ID: 9389a9a3-08cb-51ad-8486-7c917003a4b5

STIX ID: report--9389a9a3-08cb-51ad-8486-7c917003a4b5

Feed Name: GBHackers

Threat Score
72/100

Date Published: 2026-03-21

Date Updated: 2026-04-22

Author: Divya

...
...

This report documents an active, targeted campaign distributing the PureLog Stealer via localized phishing and Google Ads malvertising to organizations in healthcare, government, hospitality, and education across Germany, Canada, the United States, and Australia; it describes a multi-stage chain (decoy PDFs, remote key retrieval, fileless Python loader that patches AMSI, ConfuserEx .NET loaders, and in-memory reflective execution) and includes multiple IOCs (SHA‑256 hashes, domains, and IP addresses) for detection and response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.