logo

Attackers Hide Infostealer in Copyright Infringement Notices

ID: 9de43c8f-9bc8-5432-bcaf-5b5fbdc4904a

STIX ID: report--9de43c8f-9bc8-5432-bcaf-5b5fbdc4904a

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2026-03-23

Date Updated: 2026-04-21

Author: Elizabeth Montalbano

...
...

Trend Micro details a targeted phishing campaign that uses copyright-infringement lures to trick victims into executing a seemingly benign PDF which triggers a fileless, multistage infection chain (Python loader + dual .NET loaders) that deploys PureLog Stealer in memory. The malware employs AMSI bypasses, anti-VM/analysis checks, runtime key retrieval and heavy obfuscation to avoid detection, establishes persistence via registry changes, and steals browser credentials, extensions, crypto wallets and system information; recommended defenses include EDR/XDR with memory scanning, application allowlisting, restricting unauthorized Python execution, sandboxing suspicious legal/financial attachments, and user training.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.