PureLogs Info Stealer Campaign Exploits Trusted Windows Process
ID: 73ed6a46-5dc0-5e04-9a49-d5734da952e1
STIX ID: report--73ed6a46-5dc0-5e04-9a49-d5734da952e1
Feed Name: securityonline.info
FortiGuard Labs describes the PureLogs info-stealer campaign that targets enterprises via deceptive purchase-order phishing: a kpankocrs.js archive drops a fileless PowerShell chain that performs process hollowing into MsBuild.exe, loads an in-memory .NET stealer (zgSGkYYzqVe.dll), contacts AES-encrypted C2, and harvests browser credentials, session tokens (including Discord), crypto keys, screenshots and other sensitive data; defenders should strengthen email filtering and host monitoring.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
