Veil#Drop Campaign Uses Google Blogspot to Deliver PureLog Stealer in Memory (infosecurity-magazine.com)
0xBASE INTEL BRIEF
- Veil#Drop abuses Google Blogspot for fileless delivery of PureLog Stealer
- Multi-stage process: disguised script -> PowerShell -> XOR-encoded stages from Blogspot -> .NET reflection
- Stealer captures browser passwords, cookies, crypto wallets, host info; cookies bypass MFA
"Securonix discovered the Veil#Drop campaign abusing Google Blogspot to deliver the PureLog Stealer entirely in memory. The attack starts with a disguised script that launches PowerShell, which fetches subsequent stages from attacker-controlled Blogspot pages. The use of XOR encoding and .NET reflection evades antivirus. The stealer collects browser passwords, cookies, cryptocurrency wallets, and host info. Stolen cookies can bypass multi-factor authentication."
no comments yet.