Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. (fortinet.com) Evolving Threat Landscape: PawsRunner Steganography Loader Delivers PureLogs Infostealer via Phishing Campaigns

(fortinet.com) Evolving Threat Landscape: PawsRunner Steganography Loader Delivers PureLogs Infostealer via Phishing Campaigns

Scheduled Pinned Locked Moved Uncategorized
cybersecuritythreatintel
1 Posts 1 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • orlysec@swecyb.comO This user is from outside of this forum
    orlysec@swecyb.comO This user is from outside of this forum
    orlysec@swecyb.com
    wrote last edited by
    #1

    (fortinet.com) Evolving Threat Landscape: PawsRunner Steganography Loader Delivers PureLogs Infostealer via Phishing Campaigns

    New campaign leverages PawsRunner steganography loader to deploy PureLogs infostealer via phishing. Attack abuses environment variables, AES/RC4 encryption, and PNG-based steganography to evade detection.

    In brief - A sophisticated phishing campaign uses TXZ archives to deliver PawsRunner, a .NET loader that hides encrypted payloads in cat-themed PNGs via steganography. The final payload, PureLogs infostealer, exfiltrates data via AES-encrypted HTTP requests, demonstrating advanced evasion tactics.

    Technically - The attack begins with obfuscated JavaScript in environment variables, launching conhost.exe to execute PowerShell. PawsRunner dynamically loads payloads by decrypting RC4-encoded URLs, fetching PNGs with embedded data (iTXt/IEND chunks), and decrypting them to retrieve .NET executables. PureLogs uses AES-256-CBC and Gzip compression, harvesting data asynchronously and exfiltrating via HTTPS to multiple C2 endpoints. The loader bypasses ETW and Windows 11 (24H2) security features, employing reflection and fallback mechanisms.

    Source: https://www.fortinet.com/blog/threat-research/purelogs-delivery-via-pawsrunner-steganography

    #Cybersecurity #ThreatIntel

    1 Reply Last reply
    1
    0
    • R relay@relay.infosec.exchange shared this topic
    Reply
    • Reply as topic
    Log in to reply
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes


    • Login

    • Login or register to search.
    • First post
      Last post
    0
    • Categories
    • Recent
    • Tags
    • Popular
    • World
    • Users
    • Groups