PureLogs is a commodity .NET information stealer for Windows, marketed as a malware-as-a-service product by the PureCoder developer since 2022. It harvests browser-stored credentials, cookies, autofill and payment data, session tokens, cryptocurrency-wallet data, and credentials or authentication material from email, messaging, file-transfer, VPN, gaming, and password-management applications. It can collect host profiling data, security-product information, clipboard contents, screenshots, and selected files, then encrypt, compress, and exfiltrate collected data through its command-and-control protocol. Variants have also supported downloading and executing additional payloads.
PureLogs commonly uses commercial .NET protectors, encrypted configuration and communications, anti-debugging, anti-sandbox and anti-virtualization checks, process masquerading or injection, reflective in-memory loading, and self-deletion to impede analysis and detection. Some observed variants establish persistence through Startup-folder artifacts, scheduled tasks, or Run-key execution. Researchers have also documented variants using COM-elevation techniques. The malware is frequently delivered through phishing attachments and archive-based lures, often by multi-stage JavaScript or PowerShell loaders using process hollowing and trusted Windows binaries. It has also appeared in ClickFix campaigns and malicious software-package or extension campaigns. PureLogs has been used in campaigns targeting enterprises and organizations across multiple regions, including Russian, Japanese, and Korean victims, and has been deployed by criminal operators including activity attributed to Fluffy Wolf.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
After four stages of unpacking and injection, the PURELOGS stealer is now running inside the hollowed CasPol.exe process. PURELOGS is a commodity .NET infostealer that first appeared for sale on various underground forums in 2022.
These scripts systematically deploy the final payloads, which include the notorious Pay2Key ransomware, the PureLogs information stealer, and the PureRAT trojan.
Cyble Research and Intelligence Labs analyzes a spam campaign dropping PureLogs stealer aimed at Italian users... This tool is used by the Threat Actor (TA) “Alibaba2044” to launch a malicious spam campaign at targets based in Italy on the 14th of December 2022.
Cyble Research and Intelligence Labs analyzes a spam campaign dropping PureLogs stealer aimed at Italian users... This tool is used by the Threat Actor (TA) “Alibaba2044” to launch a malicious spam campaign at targets based in Italy on the 14th of December 2022.
35 distinct techniques documented for this family, organized by ATT&CK tactic.
it builds a PowerShell command with a Base64-encoded payload and fires it off using WMI.
Type 2-1はタスクスケジューラーにWindowsFontCacheRestoreを作成し、FontCacheSync.vbsをwscript.exeで実行する。
At first glance, the file is unreadable: It's packed with non-ASCII characters that break static analysis and mess with signature-based detection.
DLLには処理に無関係なオーバーレイが存在し、ファイルサイズは75MBである。ファイルサイズ制限のあるセキュリティー製品やサンドボックスでの解析回避を意図していると考えられる。
The attackers embedded a Base64-encoded payload after the IEND chunk of the PNG... The actual malware sits between two custom markers, BaseStart- and -BaseEnd.
запускает системную утилиту InstallUtil.exe и внедряет в ее процесс расшифрованный модуль... затем передать ей управление.
CHRDを起点として断片化データをシェルコードへ変換し、.NETローダーはPayloadSource.zipをTripleDES-CBCで復号してGZip展開する。
Type 3ではLenovo社の署名付きドライバーBootRepair.sysを同梱し、署名付きの脆弱なドライバーを悪用したBYOVDによるセキュリティー製品の停止を行う。
CasPol.exe is a legitimate .NET Framework tool (Code Access Security Policy Tool), which makes it the perfect cover. Security tools see it as a trusted Microsoft utility.
to decrypt and extract stored credentials, session cookies, autofill information, history and credit cards.
the malware compresses the entire extension data folder, which contains the encrypted seed phrases and private keys, into a ZIP archive.
Для общения с командным сервером PureRAT устанавливает SSL-соединения и передает сообщения в формате protobuf, упакованные в gzip.
PureLogsダウンローダーはGET /pingおよびPOST /plugin、/userinfo、/browser、/discord等のHTTPエンドポイントを用いて通信する。
В ответ от С2 приходит несколько сообщений, содержащих дополнительные модули (плагины) и конфигурацию к ним... способен выкачивать по переданному URL файл и запускать его.
191 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
54 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Pureマルウェアファミリーに属する情報窃取マルウェア。C2への到達確認後、プラグインを取得し、システム情報、スクリーンショット、ブラウザーのCookieおよびプロファイル、Discordデータ、ファイル検索結果を窃取・送信する。キャンペーンではPythonインタープリター、Donut loader、多重永続化、AMSI/ETW回避、プロセスホロウイング、BYOVDを含む複数の異なるローダーで展開された。
Stealer deployed as a secondary payload by DonutLoader.
An infostealer developed by PureCoder that steals credentials and other sensitive data from infected hosts and exfiltrates it over a custom binary protocol, often wrapped in TLS in newer versions.
An infostealer developed by PureCoder that steals credentials and other sensitive data from infected hosts and exfiltrates it over a custom binary protocol, often wrapped in TLS in newer versions.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.