New PawsRunner Steganography Loader Evades EDR to Deploy PureLogs Infostealer
ID: 62c5dd03-cea2-510c-a235-708c737fbaab
STIX ID: report--62c5dd03-cea2-510c-a235-708c737fbaab
Feed Name: securityonline.info
FortiGuard Labs documents a sophisticated multi-stage campaign that begins with invoice-themed phishing delivering TXZ archives containing JS/VBS which store decoded commands in environment variables to evade EDR; the chain downloads a benign-looking cat image which the .NET steganography loader PawsRunner parses to extract and reflectively load an advanced PureLogs infostealer that harvests browser credentials, session cookies, Discord tokens, and cryptocurrency wallets and exfiltrates data to C2 5.101.84.202:8996.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
