logo

New PawsRunner Steganography Loader Evades EDR to Deploy PureLogs Infostealer

ID: 62c5dd03-cea2-510c-a235-708c737fbaab

STIX ID: report--62c5dd03-cea2-510c-a235-708c737fbaab

Feed Name: securityonline.info

Threat Score
72/100

Date Published: 2026-05-21

Date Updated: 2026-05-21

Author: Ddos

...
...

FortiGuard Labs documents a sophisticated multi-stage campaign that begins with invoice-themed phishing delivering TXZ archives containing JS/VBS which store decoded commands in environment variables to evade EDR; the chain downloads a benign-looking cat image which the .NET steganography loader PawsRunner parses to extract and reflectively load an advanced PureLogs infostealer that harvests browser credentials, session cookies, Discord tokens, and cryptocurrency wallets and exfiltrates data to C2 5.101.84.202:8996.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.