Hackers Use Compromised Websites and transcript.pdf.js Lure to Deliver PureLog Stealer
Hackers are using compromised websites and a deceptive transcript.pdf.js lure to deliver PureLog Stealer through a layered, fileless infection chain that leans heavily on PowerShell, trusted cloud infrastructure, and in-memory execution. The campaign, described in the attached research, shows how modern stealers increasingly rely on social engineering and living-off-the-land techniques rather than noisy malware binaries. […]
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
