All Topics
All Topics
Technology
Technology
Design
Design
Programming
Programming
Science
Science
News
News
Gaming
Gaming
Entertainment
Entertainment
Business
Business
Finance
Finance
Sports
Sports
Health
Health
Food
Food
Travel
Travel
Art
Art
Music
Music
Books
Books
Education
Education
Politics
Politics
Personal
Personal
No algorithm. No AI slop. No ads. Just RSS. Pro-human. Indie writers. Real journalism. Open web. Chronological. Hand toasted.

FortiGuard Labs Analysis: PureLogs Infostealer Delivered via PawsRunner Steganography Campaign

5d ago· 10 min readenInsight

Summary

FortiGuard Labs analyzes a malware campaign using steganography to deliver the PureLogs infostealer. The attack begins with a phishing email containing an HTML attachment that, when opened, executes JavaScript to download a malicious .NET binary (PawsRunner). PawsRunner uses steganography to extract a hidden payload from a PNG image hosted on ImgBB, ultimately deploying PureLogs — an information stealer that targets browser credentials, cryptocurrency wallets, and other sensitive data. The article details the technical infection chain, obfuscation techniques, and detection strategies.

Key quotes

· 3 pulled
This blog outlines the malware's delivery vector and provides a technical analysis of PawsRunner and the subsequent deployment of an evolved PureLogs payload.
The functions declare a large number of Process environment variables containing garbled text. It then launches conhos
Figure 1: Attack flow
Snippet from the RSS feed
FortiGuard Labs has analyzed a steganography-based malware campaign that uses PawsRunner to deliver the PureLogs infostealer, highlighting evolving delivery methods and detection strategies.…

You might also wanna read