logo

Hidden in Plain Site: PURELOGS Stealer Hides Malware in Archive.org Images

ID: b982745b-e2dd-5e4e-be3d-84bc7e6cc646

STIX ID: report--b982745b-e2dd-5e4e-be3d-84bc7e6cc646

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-01-21

Date Updated: 2026-04-23

Author: Ddos

...
...

Swiss Post Cybersecurity analyzed a phishing campaign that distributes the PURELOGS infostealer: a JScript dropper downloads a polyglot PNG from archive.org containing a Base64 payload which a PowerShell loader executes in memory. The multi-stage attack uses VM detection, process hollowing of a legitimate .NET binary (CasPol.exe), and a 3DES unpacker to deploy an infostealer targeting browser credentials and over 30 desktop crypto wallets plus ~70 browser extensions; the malware is offered as a low-cost MaaS subscription, widening the potential impact to home users and enterprise supply chains.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.