Researchers reported that the Veil#Drop malware framework is using compromised websites, disguised scripts, PowerShell, and Google Blogspot pages to deliver the PureLog Stealer payload entirely in memory. The campaign relies on fileless execution, custom XOR encoding, and reflective loading of .NET assemblies to avoid writing artifacts to disk, while also abusing trusted Microsoft-signed binaries including InstallUtil.exe, RegSvcs.exe, and MSBuild.exe to blend malicious activity with legitimate Windows processes. PureLog Stealer is designed to harvest browser credentials, cookies, autofill data, cryptocurrency wallet information, and host details, with researchers warning that stolen session cookies may be reused to bypass MFA protections.
The activity aligns with MITRE ATT&CK technique T1218.004, which documents how attackers can misuse InstallUtil for signed binary proxy execution by triggering installer components embedded in .NET binaries. Detection guidance has highlighted InstallUtil as a high-signal LOLBIN when it uses the /u uninstall switch and establishes remote network connections, behavior associated with malicious code download, arbitrary code execution, lateral movement, and possible data exfiltration. Splunk has since consolidated that monitoring into a broader analytic for Windows InstallUtil remote network connections, underscoring continued defender focus on this execution method.

Pull IOCs and campaign context straight into your stack.
3 events from the most recent confirmed update back to the earliest known activity.
Splunk Threat Research removed the detection analytic "Windows InstallUtil Uninstall Option with Network" from its content library because its coverage was replaced by "Windows InstallUtil Remote Network Connection." The record lists the update date as 2026-05-13.
MITRE ATT&CK published documentation for sub-technique T1218.004 describing how adversaries can abuse the legitimate Windows utility InstallUtil to proxy malicious code execution and bypass application control.
Securonix Threat Research described a fileless malware framework it named Veil#Drop that uses compromised websites, disguised scripts, PowerShell, and Google Blogspot pages to deliver the PureLog Stealer entirely in memory. The campaign also uses trusted LOLBINs including InstallUtil, RegSvcs, and MSBuild as fallback execution methods.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
3 references tracked. Mallory keeps watching after this page renders.
infosecurity-magazine.com
Open sourceresearch.splunk.com
Open sourceattack.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.