Skip to content
PureLogs Infostealer Campaign Targets Users via Phishing with Cat Photos

PureLogs Infostealer Campaign Targets Users via Phishing with Cat Photos

First seen 19 May 2026, 13:54 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster May 20, 2026 at 13:40 UTC
  • PureLogs infostealer is delivered via phishing emails disguised as invoices.
  • Malicious payloads are hidden in TXZ archives containing JavaScript files.
  • The attack exploits social engineering tactics to pressure victims into opening the files.

A new phishing campaign is distributing the PureLogs infostealer, which targets Windows machines. The attack begins with an email containing a TXZ archive disguised as an urgent invoice, compelling victims to open it quickly. Once extracted, the archive reveals a JavaScript file that executes malicious commands. This tactic of hiding malware in seemingly harmless files is becoming increasingly common among threat actors. The campaign has been confirmed by Fortinet researchers, indicating a widespread impact on users globally. Specific numbers on affected users or systems were not disclosed in the articles. The attack exploits social engineering to increase the likelihood of user interaction with the malicious payload. The current status of the campaign remains active as of May 19, 2026.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 113d ago How this analysis works

Timeline

2026-05-18
Phishing campaign identified
Fortinet researchers discovered a new phishing campaign distributing PureLogs infostealer via TXZ archives.
Gbhackers
2026-05-19
PureLogs infostealer details published
HelpNet Security reported on the PureLogs infostealer campaign, confirming its global reach and use of cat photos for delivery.
Feeds2.Feedburner

More articles in this cluster (2)

Following this threat?

Track Purelogs in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed