Skip to content
Multi-Stage PureLog Stealer Campaign Targets Key Industries via Copyright Lures

Multi-Stage PureLog Stealer Campaign Targets Key Industries via Copyright Lures

First seen 21 Mar 2026, 05:41 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 23, 2026 at 16:58 UTC
  • •PureLog Stealer is delivered through phishing emails disguised as copyright complaints.
  • •The malware targets sensitive data from key sectors, including healthcare and government.
  • •The attack employs a multi-stage infection chain designed to evade detection and increase success.

A sophisticated multi-stage attack campaign is distributing PureLog Stealer, an information-stealing malware, disguised as legal copyright violation notices. The malware targets sensitive data such as browser credentials, extensions, cryptocurrency wallets, and system information. Key sectors affected include healthcare, government, hospitality, and education, particularly in Germany and Canada. The attack method involves phishing emails that lead victims to download a malicious executable. Once executed, the malware employs a multi-stage infection chain, utilizing encrypted, fileless techniques to evade detection. The campaign is characterized by its selective targeting and localized delivery, with filenames in the victim's language. Current reports indicate ongoing activity, emphasizing the need for heightened awareness and vigilance among potential targets.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 185d ago How this analysis works

Timeline

2026-03-19
Trendmicro article published detailing the PureLog Stealer campaign.
2026-03-21
Gbhackers article published, confirming ongoing distribution of PureLog Stealer.

More articles in this cluster (4)

Following this threat?

Track PureLog Stealer and Education in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed