logo

PureLogs Variant Steals Data via Purchase Order Lures

ID: 0f4c8887-bb44-53b2-aadc-20aa19cf9fc3

STIX ID: report--0f4c8887-bb44-53b2-aadc-20aa19cf9fc3

Feed Name: Infosecurity Magazine (News)

Threat Score
70/100

Date Published: 2026-05-27

Date Updated: 2026-05-27

...
...

FortiGuard Labs observed a phishing campaign using purchase-order-themed emails with a RAR-attached malicious JavaScript that decrypts and executes PowerShell to deploy a fileless PureLogs infostealer. The multi-stage chain extracts .NET modules, employs process hollowing into MsBuild.exe, downloads a DES-encrypted plugin, and exfiltrates system details, screenshots, browser credentials, Discord tokens, and cryptocurrency wallet files to a C2 server; the report includes IoCs and mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.