Copyright Lures and “Fileless” Shadows: Inside the PureLog Stealer Campaign
ID: 09db501e-9525-507f-b6d2-649156fda073
STIX ID: report--09db501e-9525-507f-b6d2-649156fda073
Feed Name: securityonline.info
Trend Micro uncovered a sophisticated, targeted campaign distributing the PureLog Stealer via localized phishing 'legal notice' lures aimed at healthcare, government, and education organizations in Germany, Canada, and the U.S.; the attack uses remotely encrypted payloads (extracted by a renamed WinRAR), a Python loader that patches AMSI to enable fileless, in-memory execution, redundant .NET loaders for resilience, registry persistence, victim fingerprinting, screenshot capture, and HTTPS exfiltration of harvested credentials and system data.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
