PureLogs is a Windows-based .NET information stealer developed by PureCoder and marketed as malware-as-a-service since 2022. It is distinct from PureRAT, the same developer's remote-access malware. PureLogs automatically harvests and exfiltrates browser-stored passwords, session cookies and tokens, browsing history, autofill records, payment-card information, and cryptocurrency-wallet data, including private keys. It targets Chromium- and Firefox-family browsers, wallet applications and browser extensions, password managers, email clients, messaging applications, file-transfer clients, and VPN software. Its collection capabilities also include screenshots, clipboard contents, selected files, and host metadata such as hardware configuration, operating-system details, usernames, and installed security products.
PureLogs uses modular components retrieved from command-and-control infrastructure to perform data collection. It can also download and execute additional files at an operator's direction. Stolen information is transmitted through encrypted command-and-control channels; implementations vary between versions and deployment chains, including custom binary protocols, encrypted and compressed messages, and TLS-wrapped communications. Samples employ commercial .NET obfuscation, anti-debugging and virtualization checks, and self-deletion to hinder analysis. Some configurations exclude Russian-language systems or selected geographic regions.
Distribution includes business-themed phishing emails carrying malicious archives or links to fraudulent document-sharing and video-preview pages, ClickFix lures that induce PowerShell execution, fake software installers, and malicious developer extensions. Delivery chains commonly use JavaScript, PowerShell, PureCrypter, or other loaders, followed by reflective .NET loading, in-memory execution, and process injection or hollowing into trusted Windows processes. Some PureLogs deployment chains additionally use DLL sideloading, scheduled-task and startup persistence, Windows scanning and logging bypasses, and vulnerable signed drivers to disable security software.
PureLogs has been deployed by Fluffy Wolf against Russian organizations in construction, consulting, manufacturing, engineering, retail, and e-commerce. Other campaigns have targeted Japanese- and Korean-language business recipients and blockchain developers.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
After four stages of unpacking and injection, the PURELOGS stealer is now running inside the hollowed CasPol.exe process. PURELOGS is a commodity .NET infostealer that first appeared for sale on various underground forums in 2022.
These scripts systematically deploy the final payloads, which include the notorious Pay2Key ransomware, the PureLogs information stealer, and the PureRAT trojan.
Cyble Research and Intelligence Labs analyzes a spam campaign dropping PureLogs stealer aimed at Italian users... This tool is used by the Threat Actor (TA) “Alibaba2044” to launch a malicious spam campaign at targets based in Italy on the 14th of December 2022.
Cyble Research and Intelligence Labs analyzes a spam campaign dropping PureLogs stealer aimed at Italian users... This tool is used by the Threat Actor (TA) “Alibaba2044” to launch a malicious spam campaign at targets based in Italy on the 14th of December 2022.
32 distinct techniques documented for this family, organized by ATT&CK tactic.
Type 2-1はタスクスケジューラーにWindowsFontCacheRestoreを作成し、FontCacheSync.vbsをwscript.exeで実行する。
At first glance, the file is unreadable: It's packed with non-ASCII characters that break static analysis and mess with signature-based detection.
DLLには処理に無関係なオーバーレイが存在し、ファイルサイズは75MBである。ファイルサイズ制限のあるセキュリティー製品やサンドボックスでの解析回避を意図していると考えられる。
« Ce malware est généralement diffusé au moyen de [...] faux logiciels [...] »
запускает системную утилиту InstallUtil.exe и внедряет в ее процесс расшифрованный модуль... затем передать ей управление.
CHRDを起点として断片化データをシェルコードへ変換し、.NETローダーはPayloadSource.zipをTripleDES-CBCで復号してGZip展開する。
Type 3ではLenovo社の署名付きドライバーBootRepair.sysを同梱し、署名付きの脆弱なドライバーを悪用したBYOVDによるセキュリティー製品の停止を行う。
CasPol.exe is a legitimate .NET Framework tool (Code Access Security Policy Tool), which makes it the perfect cover. Security tools see it as a trusted Microsoft utility.
« Il est conçu pour collecter et exfiltrer [...] les cookies de session [...] »
Для общения с командным сервером PureRAT устанавливает SSL-соединения и передает сообщения в формате protobuf, упакованные в gzip.
PureLogsダウンローダーはGET /pingおよびPOST /plugin、/userinfo、/browser、/discord等のHTTPエンドポイントを用いて通信する。
В ответ от С2 приходит несколько сообщений, содержащих дополнительные модули (плагины) и конфигурацию к ним... способен выкачивать по переданному URL файл и запускать его.
295 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
58 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Information stealer distributed in the same business-complaint phishing campaign. It collects browser cookies and profiles, Discord data, screenshots, and file-search results. Multiple delivery variants use changing loaders to conceal the payload and undermine hash-based detection. Listed command-and-control infrastructure includes logs[.]uvexio[.]com, tea[.]vexexo[.]com, trump2[.]1368[.]lol, bdp[.]edu[.]vn, and pure26[.]myftp[.]org.
A named component of the PureCoder malware ecosystem; no use in either campaign is described.
Stealer .NET fortement obfusqué that steals Chromium and Firefox credentials, session cookies, banking data, and cryptocurrency-wallet data. It excludes systems with the ru-RU language setting and communicates with its C2 using encrypted traffic.
Pureマルウェアファミリーに属する情報窃取マルウェア。C2への到達確認後、プラグインを取得し、システム情報、スクリーンショット、ブラウザーのCookieおよびプロファイル、Discordデータ、ファイル検索結果を窃取・送信する。キャンペーンではPythonインタープリター、Donut loader、多重永続化、AMSI/ETW回避、プロセスホロウイング、BYOVDを含む複数の異なるローダーで展開された。
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.