<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[(fortinet.com) Evolving Threat Landscape: PawsRunner Steganography Loader Delivers PureLogs Infostealer via Phishing Campaigns]]></title><description><![CDATA[<p>(fortinet.com) Evolving Threat Landscape: PawsRunner Steganography Loader Delivers PureLogs Infostealer via Phishing Campaigns</p><p>New campaign leverages PawsRunner steganography loader to deploy PureLogs infostealer via phishing. Attack abuses environment variables, AES/RC4 encryption, and PNG-based steganography to evade detection.</p><p>In brief - A sophisticated phishing campaign uses TXZ archives to deliver PawsRunner, a .NET loader that hides encrypted payloads in cat-themed PNGs via steganography. The final payload, PureLogs infostealer, exfiltrates data via AES-encrypted HTTP requests, demonstrating advanced evasion tactics.</p><p>Technically - The attack begins with obfuscated JavaScript in environment variables, launching conhost.exe to execute PowerShell. PawsRunner dynamically loads payloads by decrypting RC4-encoded URLs, fetching PNGs with embedded data (iTXt/IEND chunks), and decrypting them to retrieve .NET executables. PureLogs uses AES-256-CBC and Gzip compression, harvesting data asynchronously and exfiltrating via HTTPS to multiple C2 endpoints. The loader bypasses ETW and Windows 11 (24H2) security features, employing reflection and fallback mechanisms.</p><p>Source: <a href="https://www.fortinet.com/blog/threat-research/purelogs-delivery-via-pawsrunner-steganography" rel="nofollow noopener"><span>https://www.</span><span>fortinet.com/blog/threat-resea</span><span>rch/purelogs-delivery-via-pawsrunner-steganography</span></a></p><p><a href="https://swecyb.com/tags/Cybersecurity" rel="tag">#<span>Cybersecurity</span></a> <a href="https://swecyb.com/tags/ThreatIntel" rel="tag">#<span>ThreatIntel</span></a></p>]]></description><link>https://board.circlewithadot.net/topic/72e1a6cd-c3e1-452a-aad9-ff157bb30404/fortinet.com-evolving-threat-landscape-pawsrunner-steganography-loader-delivers-purelogs-infostealer-via-phishing-campaigns</link><generator>RSS for Node</generator><lastBuildDate>Mon, 25 May 2026 15:42:20 GMT</lastBuildDate><atom:link href="https://board.circlewithadot.net/topic/72e1a6cd-c3e1-452a-aad9-ff157bb30404.rss" rel="self" type="application/rss+xml"/><pubDate>Fri, 15 May 2026 17:40:47 GMT</pubDate><ttl>60</ttl></channel></rss>