logo

PureLogs: Delivery via PawsRunner Steganography

ID: 45706610-d09b-54cc-921d-602a3b7d784a

STIX ID: report--45706610-d09b-54cc-921d-602a3b7d784a

Feed Name: Fortinet Blog

Threat Score
78/100

Date Published: 2026-05-15

Date Updated: 2026-05-15

...
...

FortiGuard Labs details a phishing campaign that delivers a steganographic .NET loader called PawsRunner via a TXZ attachment and JavaScript that hides commands in environment variables; PawsRunner retrieves encrypted data hidden in PNG images (often cat photos) to load and execute the PureLogs infostealer, which collects extensive browser, wallet, application, and system data and communicates with C2 via HTTPS. The report includes a technical analysis of each stage, persistence/evasion techniques, harvested artifacts and extensions/wallets targeted, detection notes, and IOCs (IPs, URLs, SHA256 hashes).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.