PureLogs Variant Steals Data via Purchase Order Lures
ID: 0f4c8887-bb44-53b2-aadc-20aa19cf9fc3
STIX ID: report--0f4c8887-bb44-53b2-aadc-20aa19cf9fc3
Feed Name: Infosecurity Magazine (News)
FortiGuard Labs observed a phishing campaign using purchase-order-themed emails with a RAR-attached malicious JavaScript that decrypts and executes PowerShell to deploy a fileless PureLogs infostealer. The multi-stage chain extracts .NET modules, employs process hollowing into MsBuild.exe, downloads a DES-encrypted plugin, and exfiltrates system details, screenshots, browser credentials, Discord tokens, and cryptocurrency wallet files to a C2 server; the report includes IoCs and mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
