Multi-Stage PureLog Stealer Campaign Targets Key Industries via Copyright Lures

Multi-Stage PureLog Stealer Campaign Targets Key Industries via Copyright Lures

First seen 21 Mar 2026, 05:41 UTC Feeds.TrendmicroGbhackersCybersecuritynewsDarkreading 80% similarity 64.5

Article Content

Browse articles
ThreatCluster

A sophisticated multi-stage attack campaign is distributing PureLog Stealer, an information-stealing malware, disguised as legal copyright violation notices. The malware targets sensitive data such as browser credentials, extensions, cryptocurrency wallets, and system information. Key sectors affected include healthcare, government, hospitality, and education, particularly in Germany and Canada. The attack method involves phishing emails that lead victims to download a malicious executable. Once executed, the malware employs a multi-stage infection chain, utilizing encrypted, fileless techniques to evade detection. The campaign is characterized by its selective targeting and localized delivery, with filenames in the victim's language. Current reports indicate ongoing activity, emphasizing the need for heightened awareness and vigilance among potential targets.

Key Points: • PureLog Stealer is delivered through phishing emails disguised as copyright complaints. • The malware targets sensitive data from key sectors, including healthcare and government. • The attack employs a multi-stage infection chain designed to evade detection and increase success.

ThreatCluster AI How this analysis works

Timeline

2026-03-19
Trendmicro article published detailing the PureLog Stealer campaign.
2026-03-21
Gbhackers article published, confirming ongoing distribution of PureLog Stealer.

Community

Browse all →