0x

guest@0xbase ~$ read-only mode. Posting requires EU location.

Veil#Drop Campaign Uses Google Blogspot to Deliver PureLog Stealer in Memory (infosecurity-magazine.com)

· 26d ago · Report · Spotlight this ·
0xBASE INTEL BRIEF
  • Veil#Drop abuses Google Blogspot for fileless delivery of PureLog Stealer
  • Multi-stage process: disguised script -> PowerShell -> XOR-encoded stages from Blogspot -> .NET reflection
  • Stealer captures browser passwords, cookies, crypto wallets, host info; cookies bypass MFA

"Securonix discovered the Veil#Drop campaign abusing Google Blogspot to deliver the PureLog Stealer entirely in memory. The attack starts with a disguised script that launches PowerShell, which fetches subsequent stages from attacker-controlled Blogspot pages. The use of XOR encoding and .NET reflection evades antivirus. The stealer collects browser passwords, cookies, cryptocurrency wallets, and host info. Stolen cookies can bypass multi-factor authentication."

Discussion Matrix

0 segments

no comments yet.