www.infosecurity-magazine.com 5/27/2026, 8:19:01 AM · external

New PureLogs malware spreads via fake purchase order phishing

New PureLogs malware spreads via fake purchase order phishing
CyberSIXT Evidence Panel
Primary Source fortinet.com

A new variant of the PureLogs infostealer malware has been identified, distributed via phishing emails featuring fake purchase orders. These emails contain a malicious JavaScript that initiates a multi-stage infection on Windows systems. Once executed, the JavaScript decrypts PowerShell code, which is then run to extract data such as browser credentials, clipboard contents, and cryptocurrency wallet files.

This variant targets various browsers and applications, and its operation involves sophisticated techniques like process hollowing. Experts recommend improved email filtering and monitoring of PowerShell activities as countermeasures.

View Primary Source Via www.infosecurity-magazine.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline