PULSE NAME
Phishing Campaign Deploys JavaScript-Driven PureLogs Variant to Steal Sensitive Data
WHITE AlienVault 2026-05-26 Modified: 2026-05-27
12
IOCs
MEDIUM VOLUME
A sophisticated phishing campaign distributes a PureLogs variant through deceptive purchase order emails containing malicious JavaScript files. The attack chain employs obfuscated JavaScript that drops PowerShell scripts, which then use process hollowing techniques to inject .NET modules into legitimate Windows processes. The malware communicates with command-and-control infrastructure to download additional plugins. PureLogs collects extensive sensitive information including credentials from web browsers, cryptocurrency wallets, email clients, Discord, and various applications. It also captures screenshots, system information, and clipboard data. The collected data is compressed, encrypted with AES, and exfiltrated to remote servers. The campaign demonstrates advanced evasion techniques through fileless execution, multiple encryption layers, and abuse of trusted processes like MsBuild.exe, making detection challenging for traditional security solutions.
Indicators of Compromise (5 / 12 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 IPv4 URL
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA256 07cd03e2082bcb0b890cc59ce4c770d1a095ac6f1ae9cf999f5542555c56f841 2026-05-26
FileHash-SHA256 3d510977d60a44322f88100b515f06cb5ed83babc64247068d1a489595faa6c5 2026-05-26
FileHash-SHA256 670384fafb23140d96f2f8fe04a13fc8cc8e2a6e5e8c973e39b58d103c5fea92 2026-05-26
FileHash-SHA256 b90988400cced319d260c4937f334ecc364785ed5c593cd2139965e62ca58173 2026-05-26
FileHash-SHA256 e20b35a8c30e076cdd0e1df05ba1ff2e418dbd39a674f084787cc0af2fda9e95 2026-05-26