PureLogs Infostealer Campaign Targets Users via Phishing with Cat Photos

PureLogs Infostealer Campaign Targets Users via Phishing with Cat Photos

First seen 19 May 2026, 13:54 UTC GbhackersFeeds2.Feedburner 84% similarity 51.9

Article Content

Browse articles
ThreatCluster

A new phishing campaign is distributing the PureLogs infostealer, which targets Windows machines. The attack begins with an email containing a TXZ archive disguised as an urgent invoice, compelling victims to open it quickly. Once extracted, the archive reveals a JavaScript file that executes malicious commands. This tactic of hiding malware in seemingly harmless files is becoming increasingly common among threat actors. The campaign has been confirmed by Fortinet researchers, indicating a widespread impact on users globally. Specific numbers on affected users or systems were not disclosed in the articles. The attack exploits social engineering to increase the likelihood of user interaction with the malicious payload. The current status of the campaign remains active as of May 19, 2026.

Key Points: • PureLogs infostealer is delivered via phishing emails disguised as invoices. • Malicious payloads are hidden in TXZ archives containing JavaScript files. • The attack exploits social engineering tactics to pressure victims into opening the files.

ThreatCluster AI

Timeline

2026-05-18
Phishing campaign identified
Fortinet researchers discovered a new phishing campaign distributing PureLogs infostealer via TXZ archives.
Gbhackers
2026-05-19
PureLogs infostealer details published
HelpNet Security reported on the PureLogs infostealer campaign, confirming its global reach and use of cat photos for delivery.
Feeds2.Feedburner

Community

Browse all →