PureLog Stealer is a .NET-based information-stealing malware used in multi-stage intrusion chains to harvest credentials and other sensitive data from Windows systems. It is associated with campaigns targeting organizations in sectors including healthcare, government, education, hospitality, manufacturing, and finance, with observed victimology spanning countries such as Germany, Canada, the United States, Australia, Italy, Finland, and Saudi Arabia. The malware is commonly delivered through socially engineered lures, including copyright or intellectual-property violation notices, fake document files, compromised websites, phishing links, malvertising, and JavaScript-based launchers that abuse hidden file extensions to appear benign.
Operationally, PureLog Stealer is frequently deployed through fileless or low-artifact execution chains that rely on PowerShell, Python-based loaders, reflective .NET loading, and fallback abuse of trusted Microsoft-signed utilities. Observed delivery frameworks use staged decryption, XOR-encoded or TripleDES-protected payloads, GZip decompression, in-memory assembly loading, and redundant loaders to improve resilience and reduce forensic visibility. Campaigns have also used renamed legitimate tools, anti-analysis checks, AMSI bypass, process injection, and registry-based persistence.
The malware performs host reconnaissance and steals browser-stored data including saved credentials, cookies, autofill data, browsing history, session tokens, and extension-related information from major browsers such as Chrome, Edge, Firefox, Brave, Opera, and other Chromium-based browsers. It also targets cryptocurrency wallet data and can collect broader host details such as usernames, hostnames, operating system information, installed security products, and screenshots. Reporting also indicates collection from additional application categories including messaging clients, email clients, FTP software, cloud storage tools, developer utilities, remote access software, and password managers. Stolen data is packaged and exfiltrated to attacker-controlled infrastructure, often in encrypted form.
PureLog Stealer is a commodity infostealer that has appeared alongside other stealers and remote-access malware in shared loader ecosystems. Its theft of cookies and session material can enable session hijacking and downstream account compromise, including bypass of multi-factor authentication where valid session artifacts are reused. In enterprise environments, infections can serve as an initial foothold for broader criminal activity such as follow-on intrusion, business email compromise, ransomware deployment, financial theft, or long-term espionage support.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
30 distinct techniques documented for this family, organized by ATT&CK tactic.
processCmd powershell -NoProfile -WindowStyle Hidden -Command "Get-WmiObject -Namespace root/SecurityCenter2 -Class AntivirusProduct | ForEach-Object { $_.displayName }"
When opened, the script runs through wscript.exe or cscript.exe and launches powershell.exe with policy-bypass behavior.
The file svchost.exe is not the legitimate Windows component; it is a renamed python.exe used to execute Python scripts
This script is a fully functional Python loader targeting Windows systems. It is heavily obfuscated — every string is Base64-encoded and every numeric constant is hidden behind multi-term arithmetic expressions.
Notably, it downloads an encrypted payload disguised as a PDF file, then retrieves the decryption password remotely from attacker-controlled infrastructure. Instead of using built-in decryption code, the campaign abuses a renamed WinRAR utility disguised as a PNG image to extract the payload.
Process injection Figure 5. Observed process injection attempt, leveraging svchost.exe as the target process.
After successful extraction, the encrypted container is removed: This reduces forensic artifacts and removes the encrypted staging file.
The decoding logics are: Base64 Decode: The initial string is decoded. GZip Decompress: The base64 decoded output reveals a GZip header. Protobuf Deserialize: The decompressed data is deserialized
To ensure the payload run even when that path is blocked, Veil#Drop falled back on trusted Microsoft-signed binaries or LOLBINs, cycling through utilities such as RegSvcs, InstallUtil and MSBuild until one succeeded.
The routine also incorporates anti-virtual machine techniques to evade automated analysis environments.
On subsequent runs it reads this key first and exits early if it finds 1337.
the script collects three pieces of victim identity data: the machine hostname, the logged-in username, and the names of all installed antivirus products
It reports system details, security products, user information, external IP, and the path to a suspicious executable
The routine also incorporates anti-virtual machine techniques to evade automated analysis environments.
29 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An information-stealing malware delivered through a multi-stage infection chain using phishing/legal-notice lures, encrypted payloads disguised as PDFs, a renamed WinRAR extractor, a Python-based loader, AMSI bypass, registry persistence, victim fingerprinting, screenshot capture, and in-memory execution of the final .NET stealer payload.
A .NET-based information stealer delivered via the Veil#Drop framework. It performs system reconnaissance, steals browser credentials, cookies, autofill data, session tokens, browsing history, cryptocurrency wallet information, and data from messaging apps, email clients, remote access tools, FTP clients, cloud storage apps, developer tools, and password managers, then exfiltrates the collected data in encrypted form to attacker-controlled servers.
An information stealer delivered through a multi-stage, memory-resident infection chain that abuses Blogspot, PowerShell, Windows Script Host, and trusted Microsoft utilities. It steals saved browser passwords, cookies, autofill data, browsing history, cryptocurrency wallet details, and basic system information.
An information stealer that collects saved browser passwords, cookies, autofill data, wallet data, session tokens, browsing history, and system reconnaissance information.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.