logo

PureLogs infostealer is stealing credentials worldwide

ID: 1f1b4c48-3ab0-56e6-b0fb-e2cb391e6811

STIX ID: report--1f1b4c48-3ab0-56e6-b0fb-e2cb391e6811

Feed Name: Help Net Security

Threat Score
72/100

Date Published: 2026-05-19

Date Updated: 2026-05-19

Author: Zeljka Zorz

...
...

Fortinet researchers observed a phishing campaign that lures victims with invoice-themed emails containing a TXZ archive; embedded JavaScript launches a hidden PowerShell session that decodes and runs a .NET loader (PawsRunner) which fetches PNG images over HTTPS, extracts an encrypted payload via steganography, and deploys the PureLogs infostealer to harvest credentials, cookies, crypto wallets, password managers, authenticators and other application data for encrypted exfiltration.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.