Hidden in Plain Site: PURELOGS Stealer Hides Malware in Archive.org Images
ID: b982745b-e2dd-5e4e-be3d-84bc7e6cc646
STIX ID: report--b982745b-e2dd-5e4e-be3d-84bc7e6cc646
Feed Name: securityonline.info
Swiss Post Cybersecurity analyzed a phishing campaign that distributes the PURELOGS infostealer: a JScript dropper downloads a polyglot PNG from archive.org containing a Base64 payload which a PowerShell loader executes in memory. The multi-stage attack uses VM detection, process hollowing of a legitimate .NET binary (CasPol.exe), and a 3DES unpacker to deploy an infostealer targeting browser credentials and over 30 desktop crypto wallets plus ~70 browser extensions; the malware is offered as a low-cost MaaS subscription, widening the potential impact to home users and enterprise supply chains.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
