PureLog Stealer is a .NET-based information stealer observed as the final payload in multiple Windows-focused delivery campaigns. Reported delivery chains include the VEIL#DROP framework, which uses document-themed JavaScript launchers, PowerShell download cradles, Blogspot-hosted staging, XOR-protected payloads, reflective .NET loading, and fallback execution via trusted Microsoft-signed binaries such as InstallUtil.exe, MSBuild.exe, RegSvcs.exe, csc.exe, vbc.exe, ilasm.exe, and aspnet_compiler.exe. It has also been delivered through fake copyright-infringement phishing lures using compressed archives, a renamed legitimate tool such as WinRAR, a Python-based loader, dual .NET loaders, AMSI bypass, anti-VM checks, remote retrieval of decryption keys, and in-memory execution; and through commodity loader campaigns using weaponized Office documents exploiting CVE-2017-11882, malicious SVG files, ZIP/LNK chains, steganographically embedded payloads from Archive.org, trojanized TaskScheduler code, and process injection into RegAsm.exe. PureLog Stealer performs system reconnaissance and steals saved browser passwords, cookies, session tokens, autofill data, browsing history, browser extension data, and other browser-stored information from Google Chrome, Microsoft Edge, Firefox, Brave, Opera, and other Chromium-based browsers. It also targets cryptocurrency wallet data and can harvest information from messaging applications, email clients, remote access software, FTP clients, cloud storage applications, developer tools, and password managers. Additional observed behavior includes screenshot capture, collection of host, user, and antivirus information, encrypted packaging of stolen data, exfiltration to attacker-controlled servers, and persistence via registry modification including HKCU\Run\SystemSettings. Reported targeting associated with campaigns delivering PureLog Stealer includes healthcare, government, education, hospitality, manufacturing, and finance-related victims, with observed geographic targeting including Germany, Canada, the United States, Australia, Italy, Finland, and Saudi Arabia. High-confidence indicators mentioned in the content include Blogspot staging hosts htlwub00klocate[.]blogspot[.]com and cpyzaramay26[.]blogspot[.]com; staged files transcript.pdf.js, phud.dudus.docx.pdf.olp.sys, and niple.docx.odp.pdf.sys; and hashes b0f550c17a19682ff54bca418ee186ac986d0813e018b317dc0e7aebff5bf054, a048fc039ba6d1e22736c9142998de79445f878136664958f9b11156aaf1b61f, 7fa075ed827095b4531cb35f650ccf6345c3799734e4ed30d9f52e72c0711713, 7e4646d0cf91153653c5e366f98a65aad5ef363e0edeb246c809f53085971453, and 3d3342af3608399704d5daf9dc061ad1f8b243531fd9ef8497a10c6a9dd59661.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
24 distinct techniques documented for this family, organized by ATT&CK tactic.
That can help malicious traffic blend into normal web activity because the request appears to involve a familiar blog-hosting platform rather than an obviously malicious host.
the script runs through wscript.exe or cscript.exe and launches powershell.exe with policy-bypass behavior... VEIL#DROP used Blogspot-hosted URLs to stage additional scripts and payloads.
When opened, the script runs through wscript.exe or cscript.exe and launches powershell.exe with policy-bypass behavior.
The combination of compromised websites, multi-extension masquerading, trusted cloud services, XOR-obfuscated payloads, reflective .NET loading, fileless execution, and LOLBIN abuse demonstrates a deliberate effort to evade traditional antivirus solutions | the sophisticated framework abuses compromised websites, Blogspot, PowerShell, and fileless techniques to evade detection... executes subsequent payloads directly in memory.
The first file observed by researchers was named transcript.pdf.js. On systems where Windows hides known file extensions, a victim may notice the .pdf part and miss the real .js extension.
The retrieved file, named phud.dudus.docx.pdf.olp.sys, deletes the original JavaScript launcher to erase evidence
After the PowerShell stages run, VEIL#DROP decodes XOR-protected payload data and loads .NET assemblies through reflection.
Incident volume peaked in the middle period (25 events, March 10 to April 10), driven by the USD 280 million Drift heist and a surge in phishing and credential-theft campaigns targeting US-based financial institutions.
15 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A .NET-based information stealer delivered via the Veil#Drop framework. It performs system reconnaissance, steals browser credentials, cookies, autofill data, session tokens, browsing history, cryptocurrency wallet information, and data from messaging apps, email clients, remote access tools, FTP clients, cloud storage apps, developer tools, and password managers, then exfiltrates the collected data in encrypted form to attacker-controlled servers.
An information stealer delivered through a multi-stage, memory-resident infection chain that abuses Blogspot, PowerShell, Windows Script Host, and trusted Microsoft utilities. It steals saved browser passwords, cookies, autofill data, browsing history, cryptocurrency wallet details, and basic system information.
An information stealer that collects saved browser passwords, cookies, autofill data, wallet data, session tokens, browsing history, and system reconnaissance information.
A stealer delivered via copyright-themed phishing lures.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.