Skip to content
Phishing Campaign Deploys PureLogs Variant via JavaScript and MsBuild Injection

Phishing Campaign Deploys PureLogs Variant via JavaScript and MsBuild Injection

First seen 27 May 2026, 08:40 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster May 28, 2026 at 08:10 UTC
  • The phishing campaign uses purchase-order emails to distribute PureLogs malware.
  • Malicious JavaScript files execute PowerShell scripts that employ process hollowing.
  • The PureLogs variant targets sensitive data from various applications and browsers.

A new phishing campaign has been identified that distributes a variant of the PureLogs infostealer malware through deceptive purchase-order-themed emails. The campaign utilizes a malicious JavaScript file contained in a RAR archive, which, when executed, decrypts and runs a PowerShell script. This script employs process hollowing to inject a .NET downloader into the legitimate MsBuild.exe process, allowing it to evade detection. The downloader retrieves a PureLogs plugin that collects sensitive data, including browser credentials, cryptocurrency wallet information, and application credentials. The attack primarily targets Windows users and leverages advanced evasion techniques to minimize detection risks. FortiGuard Labs has provided detailed analysis and indicators of compromise (IoCs) for this campaign. Organizations are advised to enhance email filtering, restrict script execution, and monitor for unusual PowerShell activity. The campaign has been confirmed to be active as of May 2026.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 107d ago How this analysis works

Timeline

2026-05-27
Phishing campaign identified
FortiGuard Labs reported a new phishing campaign using PureLogs malware distributed through deceptive emails.
Fortinet
2026-05-27
Malicious JavaScript execution observed
The campaign's JavaScript file decrypts PowerShell code and executes it to drop a downloader in the C:\Temp folder.
Infosecurity-Magazine
2026-05-27
Process hollowing technique utilized
The dropped PowerShell script uses process hollowing to inject a downloader into MsBuild.exe, enhancing stealth.
Socprime
2026-05-28
Campaign details published
Gbhackers reported on the advanced evasion techniques used by the PureLogs variant, including layered obfuscation.
Gbhackers

More articles in this cluster (7)

Following this threat?

Track Purelogs and Flock in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed