PureLogs is a Windows-focused .NET infostealer sold as a malware-as-a-service offering and associated with the Pure family of crimeware developed by PureCoder. Active since at least 2022, it is commonly deployed as a final-stage payload by loaders and crypters such as PureCrypter, Donut-based loaders, VMDetectLoader, and steganographic or fileless delivery chains. Observed campaigns have used phishing, archive-borne JavaScript or script launchers, fake software installers, ClickFix lures, and trojanized developer tooling or extensions to deliver the malware, including operations targeting enterprises, Russian organizations, and cryptocurrency users and developers.
Its primary function is theft and exfiltration of sensitive data from infected Windows hosts. PureLogs targets browser-stored credentials, cookies, session tokens, autofill data, payment-card data, Discord and other messaging-platform tokens, VPN credentials, email-client data, FTP client data, cryptocurrency wallet applications, and numerous browser extensions tied to wallets, password managers, and authenticators. Reported targeting includes Chromium- and Gecko-based browsers as well as applications such as Outlook, Thunderbird, Foxmail, Mailbird, FileZilla, WinSCP, Steam, Telegram, Signal, Discord, OpenVPN, and Proton VPN. Multiple reports also describe theft of host profiling data, screenshots, clipboard contents, antivirus information, and other system metadata.
PureLogs commonly uses staged, memory-resident execution and defense-evasion techniques. Observed tradecraft includes heavy obfuscation and commercial protectors such as .NET Reactor and IntelliLock, anti-debugging, anti-sandbox and anti-VM checks, mutex-based single-instance control, self-deletion, reflective .NET loading, and process injection or process hollowing into trusted Windows binaries such as MsBuild.exe, InstallUtil.exe, and CasPol.exe. Some variants decrypt embedded resources and configuration data with combinations of XOR, DES or TripleDES, AES, GZip, and Protobuf-serialized configuration blobs before retrieving additional modules or configuration from command-and-control infrastructure.
Beyond credential and data theft, PureLogs has documented downloader functionality and can fetch and execute additional payloads or collect files from specified locations for exfiltration. Communications with command-and-control servers have been described using custom binary protocols, Protobuf with compression, and encrypted transport including 3DES, AES, and in newer variants TLS or HTTPS. The malware has appeared in broader intrusion chains alongside other Pure-family malware such as PureRAT and with payloads including ransomware, underscoring its role both as a commodity stealer and as an enabler of follow-on compromise.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
After four stages of unpacking and injection, the PURELOGS stealer is now running inside the hollowed CasPol.exe process. PURELOGS is a commodity .NET infostealer that first appeared for sale on various underground forums in 2022.
These scripts systematically deploy the final payloads, which include the notorious Pay2Key ransomware, the PureLogs information stealer, and the PureRAT trojan.
Cyble Research and Intelligence Labs analyzes a spam campaign dropping PureLogs stealer aimed at Italian users... This tool is used by the Threat Actor (TA) “Alibaba2044” to launch a malicious spam campaign at targets based in Italy on the 14th of December 2022.
Cyble Research and Intelligence Labs analyzes a spam campaign dropping PureLogs stealer aimed at Italian users... This tool is used by the Threat Actor (TA) “Alibaba2044” to launch a malicious spam campaign at targets based in Italy on the 14th of December 2022.
34 distinct techniques documented for this family, organized by ATT&CK tactic.
it builds a PowerShell command with a Base64-encoded payload and fires it off using WMI.
запускает системную утилиту InstallUtil.exe и внедряет в ее процесс расшифрованный модуль... затем передать ей управление.
It launches the legitimate .NET Framework utility CasPol.exe in a suspended state, removes its original code from memory, and replaces it with the decoded payload.
At first glance, the file is unreadable: It's packed with non-ASCII characters that break static analysis and mess with signature-based detection.
The attackers embedded a Base64-encoded payload after the IEND chunk of the PNG... The actual malware sits between two custom markers, BaseStart- and -BaseEnd.
No file hits disk, so basic file-based AV doesn't see it. Standard fileless execution.
Process Masquerading Question 06: PureLogs modifies its process name and command-line to appear as a legitimate Windows process.
запускает системную утилиту InstallUtil.exe и внедряет в ее процесс расшифрованный модуль... затем передать ей управление.
It launches the legitimate .NET Framework utility CasPol.exe in a suspended state, removes its original code from memory, and replaces it with the decoded payload.
Self Deletion The malware implements a self-deletion mechanism to remove traces of its execution from the infected system.
its sole purpose is to decrypt, decompress, and execute the final payload entirely within memory.
CasPol.exe is a legitimate .NET Framework tool (Code Access Security Policy Tool), which makes it the perfect cover. Security tools see it as a trusted Microsoft utility.
запускает системную утилиту InstallUtil.exe и внедряет в ее процесс расшифрованный модуль.
Sandbox Detection: Identifies and avoids known malware analysis environments
The malware scans for common debugging and network analysis tools to avoid running in monitored environments
Core Capabilities Browser Credential Extraction: Steals saved passwords and session cookies from major browsers Application Token Harvesting: Targets Discord, Telegram, Steam, and FileZilla authentication data Cryptocurrency Wallet Theft: Extracts wallet information and private keys
to decrypt and extract stored credentials, session cookies, autofill information, history and credit cards.
the malware compresses the entire extension data folder, which contains the encrypted seed phrases and private keys, into a ZIP archive.
The malware prevents multiple instances of a program from running simultaneously using the Windows Registry as a lock mechanism. It first checks ... searches for a specific registry key under HKEY_CURRENT_USER\Software\
System Reconnaissance: Collects detailed hardware and software information
Sandbox Detection: Identifies and avoids known malware analysis environments
Для общения с командным сервером PureRAT устанавливает SSL-соединения и передает сообщения в формате protobuf, упакованные в gzip.
119 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
53 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Stealer deployed as a secondary payload by DonutLoader.
An infostealer developed by PureCoder that steals credentials and other sensitive data from infected hosts and exfiltrates it over a custom binary protocol, often wrapped in TLS in newer versions.
An infostealer developed by PureCoder that steals credentials and other sensitive data from infected hosts and exfiltrates it over a custom binary protocol, often wrapped in TLS in newer versions.
A .NET-based information stealer delivered via the VEIL#DROP multi-stage attack chain. It harvests sensitive data from compromised systems and is loaded through reflective code loading after staged PowerShell-based delivery and evasion steps.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.