logo

Phishing Campaign Deploys JavaScript-Driven PureLogs Variant to Steal Sensitive Data

ID: 53b463e2-c76d-565e-a550-82cdc96025e1

STIX ID: report--53b463e2-c76d-565e-a550-82cdc96025e1

Feed Name: Fortinet Blog

Threat Score
78/100

Date Published: 2026-05-26

Date Updated: 2026-07-20

...
...

FortiGuard Labs analyzed a high-risk phishing campaign that uses a purchase-order-themed email to deliver a RAR containing obfuscated JavaScript; the JS drops and executes an encrypted PowerShell script which performs fileless .NET process hollowing to load a downloader that retrieves a fileless PureLogs infostealer plugin from a C2 (77.83.39.211:8443). The PureLogs variant collects extensive sensitive data (browser credentials, crypto wallets, Discord tokens, system info, screenshots) and exfiltrates it via AES/GZIP-protected HTTP endpoints; the report includes IOCs (URLs, IP, sample SHA-256s) and recommended mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.