Infosecurity-Magazine Phishing Campaign Deploys PureLogs Variant via JavaScript and MsBuild Injection
Article Content
- •The phishing campaign uses purchase-order emails to distribute PureLogs malware.
- •Malicious JavaScript files execute PowerShell scripts that employ process hollowing.
- •The PureLogs variant targets sensitive data from various applications and browsers.
A new phishing campaign has been identified that distributes a variant of the PureLogs infostealer malware through deceptive purchase-order-themed emails. The campaign utilizes a malicious JavaScript file contained in a RAR archive, which, when executed, decrypts and runs a PowerShell script. This script employs process hollowing to inject a .NET downloader into the legitimate MsBuild.exe process, allowing it to evade detection. The downloader retrieves a PureLogs plugin that collects sensitive data, including browser credentials, cryptocurrency wallet information, and application credentials. The attack primarily targets Windows users and leverages advanced evasion techniques to minimize detection risks. FortiGuard Labs has provided detailed analysis and indicators of compromise (IoCs) for this campaign. Organizations are advised to enhance email filtering, restrict script execution, and monitor for unusual PowerShell activity. The campaign has been confirmed to be active as of May 2026.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (7)
Following this threat?
Track Purelogs and Flock in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
Critical GitLab Vulnerabilities Exploited Within Hours of Disclosure On September 10, 2026, GitLab released patches for critical vulnerabilities CVE-2026-85706 and CVE-2026-87719. CVE-2026-85706, a path traversal flaw, allows unauthenticated users to read arbitrary files from GitLab servers, while CVE-2026-87719 enables credential theft via insecure deserialization. Both…