PureLog Stealer is a .NET-based information stealer used in multiple phishing- and loader-driven intrusion chains targeting Windows systems. It is commonly delivered through multi-stage, fileless or low-artifact execution frameworks that rely on social engineering, malicious script launchers, PowerShell download cradles, reflective .NET loading, and abuse of trusted Windows utilities to evade detection. Observed delivery themes include fake copyright infringement notices, deceptive document-style files, compromised websites, and ClickFix-style lures that trick users into executing malicious commands. PureLog Stealer has also appeared as a final payload in commodity loader ecosystems that use steganography, archive-based staging, and process injection.
Once executed, PureLog Stealer performs host reconnaissance and harvests sensitive data from major browsers including Chrome, Edge, Firefox, Brave, Opera, and other Chromium-based browsers. Reported collection includes saved credentials, cookies, session tokens, autofill data, browsing history, browser extension data, and cryptocurrency wallet information. Some reporting also attributes collection from messaging applications, email clients, FTP clients, cloud storage applications, developer tools, remote access software, and password managers. In certain campaigns it additionally captures screenshots and system profiling data. Stolen data is packaged and exfiltrated to attacker-controlled infrastructure, often in encrypted form.
The malware is associated with campaigns against healthcare, government, education, hospitality, manufacturing, and finance-related targets, with observed victimology spanning Europe, North America, the Middle East, and Australia. Delivery chains linked to PureLog Stealer frequently emphasize defense evasion through in-memory execution, obfuscation, AMSI bypass, anti-analysis checks, reflective assembly loading, fallback execution via LOLBINs, and in some cases process injection or hollowing. Successful compromise can enable downstream account takeover and broader enterprise intrusion because stolen credentials and session material may be reused or sold for follow-on operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
20 distinct techniques documented for this family, organized by ATT&CK tactic.
Because Windows hides known extensions by default, it appeared to be a PDF, but it was actually a script that Windows Script Host runs, launching PowerShell with security checks disabled. From there, PowerShell fetched its next stages directly from attacker-controlled Blogspot pages and run them in memory, without writing any files to disk.
When opened, the script runs through wscript.exe or cscript.exe and launches powershell.exe with policy-bypass behavior.
The later stages hid their contents behind custom XOR encoding and only decoded at runtime.
The attack begun when a victim on a compromised website opened a file masquerading as a document. Because Windows hides known extensions by default, it appeared to be a PDF, but it was actually a script that Windows Script Host runs
The retrieved file, named phud.dudus.docx.pdf.olp.sys, deletes the original JavaScript launcher to erase evidence
After the PowerShell stages run, VEIL#DROP decodes XOR-protected payload data and loads .NET assemblies through reflection.
15 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A .NET-based information stealer delivered via the Veil#Drop framework. It performs system reconnaissance, steals browser credentials, cookies, autofill data, session tokens, browsing history, cryptocurrency wallet information, and data from messaging apps, email clients, remote access tools, FTP clients, cloud storage apps, developer tools, and password managers, then exfiltrates the collected data in encrypted form to attacker-controlled servers.
An information stealer delivered through a multi-stage, memory-resident infection chain that abuses Blogspot, PowerShell, Windows Script Host, and trusted Microsoft utilities. It steals saved browser passwords, cookies, autofill data, browsing history, cryptocurrency wallet details, and basic system information.
An information stealer that collects saved browser passwords, cookies, autofill data, wallet data, session tokens, browsing history, and system reconnaissance information.
A .NET infostealer delivered via the Veil#Drop fileless framework. It is loaded entirely in memory using multi-stage PowerShell and .NET assembly loading, and steals browser credentials, cookies, autofill data, cryptocurrency wallets, and host details.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.