Phishing Campaign Deploys JavaScript-Driven PureLogs Variant to Steal Sensitive Data
ID: 53b463e2-c76d-565e-a550-82cdc96025e1
STIX ID: report--53b463e2-c76d-565e-a550-82cdc96025e1
Feed Name: Fortinet Blog
FortiGuard Labs analyzed a high-risk phishing campaign that uses a purchase-order-themed email to deliver a RAR containing obfuscated JavaScript; the JS drops and executes an encrypted PowerShell script which performs fileless .NET process hollowing to load a downloader that retrieves a fileless PureLogs infostealer plugin from a C2 (77.83.39.211:8443). The PureLogs variant collects extensive sensitive data (browser credentials, crypto wallets, Discord tokens, system info, screenshots) and exfiltrates it via AES/GZIP-protected HTTP endpoints; the report includes IOCs (URLs, IP, sample SHA-256s) and recommended mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
