Purelogs Malware — Analysis, Campaigns & Threat Activity

Threat entity extracted from intelligence sources

Frequency
7
occurrences
First Seen
January 21, 2026
Last Seen
May 28, 2026

Purelogs is a malware family tracked across 3 threat clusters and 7 intelligence report mentions on ThreatCluster. First observed January 21, 2026; most recent activity May 28, 2026.

Overview

PURELOGS is a malware family that is being delivered via weaponized PNG files. Security researchers note that the payload is hidden within the PNG images to enable stealthy execution and avoid detection, highlighting an emerging delivery vector that abuses common image formats for malware delivery.

Related Threat Clusters

Recent Intelligence Reports

  • New PureLogs Variant Abuses MSBuild to Evade Detection — Gbhackers · May 28, 2026
  • JavaScript Phishing Delivers PureLogs via MsBuild Injection — Socprime · May 27, 2026
  • Phishing Campaign Deploys Javascript Driven Purelogs Variant To Steal Sensitive Data — www.fortinet.com · May 27, 2026
  • PureLogs Variant Steals Data via Purchase Order Lures — Infosecurity-Magazine · May 27, 2026
  • PureLogs infostealer is stealing credentials worldwide — Feeds2.Feedburner · May 19, 2026
  • Threat Actors Hiding stealthy PURELOGS Payload Within a Weaponized PNG File — Cybersecuritynews · January 21, 2026
  • PURELOGS Payload Hidden in Weaponized PNG Images Used in Stealth Attacks — Gbhackers · January 21, 2026

CVSS v3.1 Breakdown