Close Menu
Tech Nova Mindset – Empower Innovation and Forward Thinking

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Young organs may not be a fountain of youth for recipients

    September 25, 2026

    How Would AI Actually Kill All Humans? Here Are the Top 5 Scenarios

    September 25, 2026

    Social Media Bans for Kids Need Smarter Safety Design

    September 25, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Young organs may not be a fountain of youth for recipients
    • How Would AI Actually Kill All Humans? Here Are the Top 5 Scenarios
    • Social Media Bans for Kids Need Smarter Safety Design
    • The Pentagon wants $30 million to build an AI-powered lie detector
    • Google’s Gemini Can Now Make Calls for You on Pixel Phones
    • EPICS in IEEE Team Builds Portable Educational Platform
    • A Digital Cell Predicts Which Drugs Will Be Most Effective in Deadly Breast Cancer
    • I Think I Found an AI Agent Worth the Risk
    Tech Nova Mindset – Empower Innovation and Forward Thinking
    • Home
    • Gadgets
    • Reviews
    • Tech News
    • Future Tech
    • AI & Robotics
    • How-To Guides
    • More
      • Cybersecurity
      • Startups & Innovation
    Tech Nova Mindset – Empower Innovation and Forward Thinking
    Home»Cybersecurity»PureLogs infostealer is stealing credentials worldwide
    Cybersecurity

    PureLogs infostealer is stealing credentials worldwide

    kirklandc008@gmail.comBy kirklandc008@gmail.comMay 19, 2026No Comments3 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    PureLogs infostealer is stealing credentials worldwide
    Share
    Facebook Twitter LinkedIn Pinterest Email

    A phishing campaign is smuggling the powerful PureLogs information stealer onto targets’ Windows machines by hiding encrypted malicious payloads inside cat photos, Fortinet researchers discovered.

    The attack

    The attack starts with a phishing email containing a TXZ archive and using an invoice-themed lure to pressure the victim into opening it quickly:

    The phishing email carrying the malicious TXZ archive (Source: Fortinet)

    The extracted JavaScript stores malicious commands in process environment variables (which are also filled with garbled text and multilingual comments as obfuscation), then launches a hidden PowerShell session to decode, decrypt, and decompress a .NET assembly loader dubbed PawsRunner.

    PawsRunner decrypts a download URL using RC4, then tries multiple network APIs to fetch a PNG image. (In a previous campaign flagged by Swiss Post Cybersecurity, the PNG image was retrieved from archive.org.)

    It then extracts an encrypted payload hidden withing the image (PNG) file using steganography markers, and bypasses Event Tracing for Windows and Windows 11 security features.

    A prodigious infostealer

    The final malicious payload is the PureLogs infostealer, which profiles the victim’s system environment and harvests credentials, cookies and session tokens from:

    • An extensive list of popular and lesser known web browsers used around the world
    • Over 100 crypto wallet extensions and desktop wallets
    • Communication apps (Discord, Telegram, Signal, etc.)
    • Password managers (Bitwarden, LastPass, 1Password, etc.)
    • Authenticators (via browser extensions)
    • Other software like Steam, OpenVPN, PhontanVPN, Ngrok, OBS Studio, FileZilla, WinSCP, FoxMail, MailBird, MailMaster, and Outlook.

    The stolen data is AES-encrypted and exfiltrated.

    “This version of PureLogs uses extensive async/await patterns to improve task efficiency and complicate analysis. Additionally, it uses HTTPS for its Command and Control (C2) communications,” the researchers added.

    The stolen data can be used for financial theft or sold on criminal markets, potentially enabling follow-on attacks against victims’ employers, banks, or contacts.

    Steganography on the rise

    The shift toward hiding payloads inside image files represents a deliberate effort to blend malicious activity into normal-looking network traffic: A PNG file fetched over HTTPS, from what might appear to be a legitimate host, raises far fewer alarms than a direct download of an executable.

    According to Fortinet, the technique is increasingly used by attackers.

    Users are advised to treat unexpected emails and attachments as suspicious regardless of how urgent or routine they look, and to be wary of opening files in unusual file formats.

    Organizations can do more: they can train employees on how to detect invoice-themed lures, block uncommon archive formats at the email gateway, monitor for unusual PowerShell behavior, restrict JavaScript execution from email attachments, and deploy endpoint detection that covers in-memory execution.

    Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

    credentials infostealer PureLogs stealing worldwide
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    kirklandc008@gmail.com
    • Website

    Related Posts

    Ransomware in 2026: More groups, more victims, no slowdown

    July 26, 2026

    The 3 types of people who will excel in the AI agent era, according to tech leaders

    July 26, 2026

    Steam forum ClickFix attacks infect gamers with XMRig cryptominers

    July 26, 2026
    Leave A Reply Cancel Reply

    Top Posts

    Nothing CEO says phone prices are going to keep going up

    June 12, 20267 Views

    The best VPN routers of 2026: Expert tested and reviewed

    June 14, 20263 Views

    Google DeepMind Plans to Track AGI Progress With These 10 Traits of General Intelligence

    March 21, 20263 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Recent Posts
    • Young organs may not be a fountain of youth for recipients
    • How Would AI Actually Kill All Humans? Here Are the Top 5 Scenarios
    • Social Media Bans for Kids Need Smarter Safety Design
    • The Pentagon wants $30 million to build an AI-powered lie detector
    • Google’s Gemini Can Now Make Calls for You on Pixel Phones

    Young organs may not be a fountain of youth for recipients

    September 25, 2026

    How Would AI Actually Kill All Humans? Here Are the Top 5 Scenarios

    September 25, 2026

    Social Media Bans for Kids Need Smarter Safety Design

    September 25, 2026

    The Pentagon wants $30 million to build an AI-powered lie detector

    September 25, 2026
    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer
    © 2026 TechNovaMindset. Designed by By Pro.

    Type above and press Enter to search. Press Esc to cancel.