PureLogs Variant Steals Data via Purchase Order Lures (infosecurity-magazine.com)
0xBASE INTEL BRIEF
- Phishing emails use fake purchase order themes with RAR archives containing JavaScript.
- Multi-stage infection chain: JavaScript -> PowerShell -> .NET modules -> process hollowing via MsBuild.exe.
- Targets: browser credentials, cryptocurrency wallets, Discord tokens, Outlook, FileZilla, OpenVPN, ProtonVPN.
"FortiGuard Labs reports a PureLogs phishing campaign using fake purchase order emails with an attached RAR archive containing a malicious JavaScript file. The infection chain uses PowerShell decryption, .NET modules in memory, and process hollowing to inject the PureLogs infostealer. It targets browser credentials, cryptocurrency wallets, Discord tokens, and application credentials."
#Purchase order phishing
#PureLogs infostealer
#Process hollowing
no comments yet.