logo

PureLogs Info Stealer Campaign Exploits Trusted Windows Process

ID: 73ed6a46-5dc0-5e04-9a49-d5734da952e1

STIX ID: report--73ed6a46-5dc0-5e04-9a49-d5734da952e1

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-05-29

Date Updated: 2026-05-29

Author: Ddos

...
...

FortiGuard Labs describes the PureLogs info-stealer campaign that targets enterprises via deceptive purchase-order phishing: a kpankocrs.js archive drops a fileless PowerShell chain that performs process hollowing into MsBuild.exe, loads an in-memory .NET stealer (zgSGkYYzqVe.dll), contacts AES-encrypted C2, and harvests browser credentials, session tokens (including Discord), crypto keys, screenshots and other sensitive data; defenders should strengthen email filtering and host monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.