PureLogs Stealer is a Windows information-stealing malware family focused on harvesting saved credentials and other stored data from web browsers, cryptocurrency wallets, messaging applications, and installed applications. Observed implementations use heavily obfuscated .NET and PowerShell-based multi-stage execution chains, including Base64-decoded payloads, in-memory .NET assembly loading, and process injection. Campaigns have used browser instances launched with reduced sandboxing controls to collect saved browser credentials. PureLogs Stealer has been delivered through phishing lures, including fake document-signing themes, with payload material reconstructed from process environment variables and concealed in image metadata. Observed activity has also established user-level logon-script persistence. The family has appeared in financially motivated crimeware operations alongside STXRAT, PureHVNC, PureRAT, ResolverRAT, and other commodity malware, and has been associated with loader-mediated execution in trojanized software campaigns.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
33 distinct techniques documented for this family, organized by ATT&CK tactic.
Stealth Packer is a new packer that... creates hidden ghost scheduled tasks... EdgeUpdateHelper Scheduled Task ... Set to run ... AdobeCloudHelper.exe daily
The decoded base64 is a powershell script... Finally, the output is executed via a powershell.
Registry Key "HKCU\Environment\UserinitMprLogonScript"
Stealth Packer is a new packer that... creates hidden ghost scheduled tasks... EdgeUpdateHelper Scheduled Task ... Set to run ... AdobeCloudHelper.exe daily
« Recherche le PID de svchost.exe (fallback sur explorer.exe) [et] injecte via la chaîne classique OpenProcess → VirtualAllocEx (0x40) → WriteProcessMemory → CreateRemoteThread. »
The sample contains long strings assigned to extremely long variable names; these variables are declared but never used. A Base64-encoded PowerShell script is embedded in the variable content.
the attackers progressively reconstruct the payload through process environment variables, PowerShell, RC4 decryption, and PNG iTXt metadata before executing PureLogs Stealer entirely in memory
The article's TTP list explicitly identifies « T1027.007 — Obfuscated Files or Information: Dynamic API Resolution ».
This blog details an investigation into malicious GitHub repositories posing as OpenClaw installers... At first glance, the GitHub repository could easily be mistaken for a legitimate installer.
« Recherche le PID de svchost.exe (fallback sur explorer.exe) [et] injecte via la chaîne classique OpenProcess → VirtualAllocEx (0x40) → WriteProcessMemory → CreateRemoteThread. »
The article's TTP list explicitly identifies « T1055.001 — Process Injection: Dynamic-link Library Injection ».
The article's TTP list explicitly identifies « T1055.003 — Process Injection: Thread Execution Hijacking ».
The PowerShell script downloads DetahNoteJ.txt, loads the content into a variable, then Base64 decodes that content, eventually storing it in a variable called $assembly.
« Anti-VM/sandbox : requêtes WMI (fabricant, GPU, CPU, température), énumération des imprimantes et périphériques USB. »
« requêtes WMI (fabricant, GPU, CPU, température), énumération des imprimantes et périphériques USB ».
« credentials navigateurs Chromium/Firefox (Login Data, Web Data, cookies de session) ».
The article's TTP list explicitly identifies « T1012 — Query Registry ».
« Anti-VM/sandbox : requêtes WMI (fabricant, GPU, CPU, température), énumération des imprimantes et périphériques USB. »
Command and Control Fallback Channels T1008 22 C2 IPs, 8 domains, 10+ port options
outbound connections to staging services such as PixelDrain provides valuable detection opportunities
76 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A multi-stage .NET stealer delivered via fake Adobe Sign phishing that uses social engineering, browser fingerprinting, fileless execution, RC4 decryption, and PNG iTXt steganography to reconstruct and execute its payload entirely in memory while evading detection.
PureLogs Stealer is used for credential theft. It injects into calc.exe and launches headless Chrome and Edge instances with no-sandbox flags to harvest saved browser credentials, using legitimate browser binaries to evade some detections.
Credential-stealing malware that harvests data from browsers, wallets, and applications. It is deployed alongside RAT and HVNC components in the same campaign.
PureLogs Stealer is an information stealer. Here it was suspected to be executed in memory by a Rust-based loader packed with Stealth Packer and connected back to attacker infrastructure.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.