Attackers Hide Infostealer in Copyright Infringement Notices
ID: 9de43c8f-9bc8-5432-bcaf-5b5fbdc4904a
STIX ID: report--9de43c8f-9bc8-5432-bcaf-5b5fbdc4904a
Feed Name: Dark Reading
Trend Micro details a targeted phishing campaign that uses copyright-infringement lures to trick victims into executing a seemingly benign PDF which triggers a fileless, multistage infection chain (Python loader + dual .NET loaders) that deploys PureLog Stealer in memory. The malware employs AMSI bypasses, anti-VM/analysis checks, runtime key retrieval and heavy obfuscation to avoid detection, establishes persistence via registry changes, and steals browser credentials, extensions, crypto wallets and system information; recommended defenses include EDR/XDR with memory scanning, application allowlisting, restricting unauthorized Python execution, sandboxing suspicious legal/financial attachments, and user training.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
