PureLogs is a Windows-based .NET information stealer sold as a commodity malware-as-a-service offering since 2022 and associated with the Pure family of products developed by PureCoder. It is designed to harvest credentials, cookies, session tokens, autofill data, credit card data, browser history, Windows secrets, password manager data, cryptocurrency wallet files and keys, and data from numerous applications including Discord, Telegram, Steam, FileZilla, Outlook, Foxmail, MailBird, MailMaster, OpenVPN, ProtonVPN, Pidgin, and DownloadManager. Reported targeting includes more than 30 desktop cryptocurrency wallets, dozens of browsers, and large numbers of browser-based Web3 wallet extensions.
Observed delivery vectors include phishing campaigns using invoice- and purchase-order-themed lures, ZIP/RAR/TXZ archives containing malicious JavaScript or Windows Script Host JScript, ClickFix-style PowerShell execution, Blogger-hosted staging, archive.org-hosted polyglot PNG payloads, and steganographic PNG retrieval via the PawsRunner loader. PureLogs has also been delivered through malicious developer tooling, including a fake Solidity extension in Cursor AI/Open VSX, and has appeared in broader intrusion chains alongside malware such as PureCrypter, PureRAT, Pay2Key, Vidar, Quasar, Violet RAT, Remcos, and PowerLoader. Threat reporting links its use to campaigns attributed or associated with Fluffy Wolf, Hive0131 with low confidence, and the SERPENTINE#CLOUD activity cluster; Huntress also documented PureLogs in fake OpenClaw installer activity.
Behaviorally, PureLogs commonly executes filelessly and in memory, often after layered decryption, decompression, and reflective .NET loading. Multiple campaigns used process hollowing or injection into legitimate signed processes including CasPol.exe, MsBuild.exe, RegAsm.exe, InstallUtil.exe, and notepad.exe-context loaders. Samples and campaigns described anti-debugging, anti-sandbox, and anti-VM checks; process masquerading; mutex or registry-based single-instance control; self-deletion; and protection or obfuscation with .NET Reactor, IntelliLock, or ConfuserEx. Reported anti-analysis checks include virtualization artifact detection, debugger and tooling checks, sandbox heuristics, and geographic filtering to avoid CIS and Russian-speaking regions in at least one analyzed sample.
Configuration and communications vary by build and campaign. Reported implementations include Protobuf-serialized and XOR-encrypted configuration blobs, 3DES- or TripleDES-decrypted resources, AES-256-CBC encryption for exfiltration, PBKDF2-derived keys in some samples, gzip compression, HTTPS or raw TCP C2, and endpoint patterns such as /ping, /plugin, /userinfo, /browser, /application, /crypto, /discord, /filesearch/req, /filesearch/res, and /finish. PureLogs has been observed profiling victims via WMI and collecting host metadata such as username, domain, CPU, GPU, RAM, OS version, architecture, screen resolution, antivirus products, clipboard contents, screenshots, public IP, timezone, and geolocation.
Known indicators mentioned in reporting include C2 or delivery infrastructure such as 45.137.70.55:5888, 77.83.39.211:8443, 5.101.84.202, 178.16.52.232, 158.94.208.92, 144.172.112.84, canndelta.com, everycarebd.com/imagelkjh0987.png, archive.org-hosted PNG payloads, and angelic.su and lmfao.su infrastructure used in a developer-targeting campaign. Detection names cited in the content include HEUR:Trojan-PSW.MSIL.PureLogs.gen, JS/PureLogs.JAE!tr, PowerShell/PureLogs.DUQ!tr, MSIL/PureLogs.C702!tr, MSIL/PureLogs.YBT!tr, and MSIL/PureLogs.0EDE!tr.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
After four stages of unpacking and injection, the PURELOGS stealer is now running inside the hollowed CasPol.exe process. PURELOGS is a commodity .NET infostealer that first appeared for sale on various underground forums in 2022.
These scripts systematically deploy the final payloads, which include the notorious Pay2Key ransomware, the PureLogs information stealer, and the PureRAT trojan.
Cyble Research and Intelligence Labs analyzes a spam campaign dropping PureLogs stealer aimed at Italian users... This tool is used by the Threat Actor (TA) “Alibaba2044” to launch a malicious spam campaign at targets based in Italy on the 14th of December 2022.
Cyble Research and Intelligence Labs analyzes a spam campaign dropping PureLogs stealer aimed at Italian users... This tool is used by the Threat Actor (TA) “Alibaba2044” to launch a malicious spam campaign at targets based in Italy on the 14th of December 2022.
35 distinct techniques documented for this family, organized by ATT&CK tactic.
It's suspected that the initial payloads are distributed either via spear-phishing or a drive-by compromise, which occurs when an unsuspecting user lands on a website (legitimate or otherwise) under the attacker's control.
it builds a PowerShell command with a Base64-encoded payload and fires it off using WMI.
it builds a PowerShell command with a Base64-encoded payload and fires it off using WMI. It launches a hidden PowerShell process and runs the decoded payload in memory with Invoke-Expression.
the loader employs a classic, well-documented process injection technique known as RunPE , or process hollowing
It launches the legitimate .NET Framework utility CasPol.exe in a suspended state, removes its original code from memory, and replaces it with the decoded payload.
At first glance, the file is unreadable: It's packed with non-ASCII characters that break static analysis and mess with signature-based detection.
The attackers embedded a Base64-encoded payload after the IEND chunk of the PNG... The actual malware sits between two custom markers, BaseStart- and -BaseEnd.
No file hits disk, so basic file-based AV doesn't see it. Standard fileless execution.
Process Masquerading Question 06: PureLogs modifies its process name and command-line to appear as a legitimate Windows process.
the loader employs a classic, well-documented process injection technique known as RunPE , or process hollowing
It launches the legitimate .NET Framework utility CasPol.exe in a suspended state, removes its original code from memory, and replaces it with the decoded payload.
terminate selected processes such as "wscript.exe" to minimize forensic trail, delete "transcript.pdf.js" to eliminate evidence of execution
Self Deletion The malware implements a self-deletion mechanism to remove traces of its execution from the infected system.
its sole purpose is to decrypt, decompress, and execute the final payload entirely within memory.
CasPol.exe is a legitimate .NET Framework tool (Code Access Security Policy Tool), which makes it the perfect cover. Security tools see it as a trusted Microsoft utility.
Sandbox Detection: Identifies and avoids known malware analysis environments
The malware scans for common debugging and network analysis tools to avoid running in monitored environments
Core Capabilities Browser Credential Extraction: Steals saved passwords and session cookies from major browsers Application Token Harvesting: Targets Discord, Telegram, Steam, and FileZilla authentication data Cryptocurrency Wallet Theft: Extracts wallet information and private keys
to decrypt and extract stored credentials, session cookies, autofill information, history and credit cards.
the malware compresses the entire extension data folder, which contains the encrypted seed phrases and private keys, into a ZIP archive.
The malware prevents multiple instances of a program from running simultaneously using the Windows Registry as a lock mechanism. It first checks ... searches for a specific registry key under HKEY_CURRENT_USER\Software\
System Reconnaissance: Collects detailed hardware and software information
Sandbox Detection: Identifies and avoids known malware analysis environments
106 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
47 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A .NET-based information stealer delivered via the VEIL#DROP multi-stage attack chain. It harvests sensitive data from compromised systems and is loaded through reflective code loading after staged PowerShell-based delivery and evasion steps.
Information stealer that harvests browser credentials, search histories, and application data, with stolen data categorized and routed to dedicated server endpoints.
Information-stealing malware delivered via malicious PowerShell in a ClickFix campaign. It uses fileless execution, Donut shellcode, RWX memory allocation, and in-memory .NET assembly loading to evade detection, then steals browser credentials, Windows secrets, cryptocurrency wallet data, password manager information, and session tokens. It also uses TCP-based C2 to exfiltrate stolen data and receive attacker-controlled configurations.
A multi-stage, fileless information stealer delivered via phishing emails disguised as purchase orders. It uses JavaScript, PowerShell, in-memory .NET modules, process hollowing into MsBuild.exe, encrypted C2 communications, and an obfuscated DLL payload to steal screenshots, hardware details, clipboard data, browser credentials and cookies, Discord tokens, cryptocurrency wallet data, email client data, and FileZilla data.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.