Last seven days
- First activity
- Aug 27, 2026
- Last activity
- Sep 2, 2026
- Feed role
- C2 / Distribution
- Host form
- 4 IP / 5 hostnames
PureLogs is a Windows-focused .NET infostealer sold as a malware-as-a-service offering and associated with the Pure family of crimeware developed by PureCoder.
Profile source: Mallory opens in a new tabPureLogs
PureLogs is a Windows-focused .NET infostealer sold as a malware-as-a-service offering and associated with the Pure family of crimeware developed by PureCoder. Active since at least 2022, it is commonly deployed as a final-stage payload by loaders and crypters such as PureCrypter, Donut-based loaders, VMDetectLoader, and steganographic or fileless delivery chains. Observed campaigns have used phishing, archive-borne JavaScript or script launchers, fake software installers, ClickFix lures, and trojanized developer tooling or extensions to deliver the malware, including operations targeting enterprises, Russian organizations, and cryptocurrency users and developers.
Its primary function is theft and exfiltration of sensitive data from infected Windows hosts. PureLogs targets browser-stored credentials, cookies, session tokens, autofill data, payment-card data, Discord and other messaging-platform tokens, VPN credentials, email-client data, FTP client data, cryptocurrency wallet applications, and numerous browser extensions tied to wallets, password managers, and authenticators. Reported targeting includes Chromium- and Gecko-based browsers as well as applications such as Outlook, Thunderbird, Foxmail, Mailbird, FileZilla, WinSCP, Steam, Telegram, Signal, Discord, OpenVPN, and Proton VPN. Multiple reports also describe theft of host profiling data, screenshots, clipboard contents, antivirus information, and other system metadata.
PureLogs commonly uses staged, memory-resident execution and defense-evasion techniques. Observed tradecraft includes heavy obfuscation and commercial protectors such as .NET Reactor and IntelliLock, anti-debugging, anti-sandbox and anti-VM checks, mutex-based single-instance control, self-deletion, reflective .NET loading, and process injection or process hollowing into trusted Windows binaries such as MsBuild.exe, InstallUtil.exe, and CasPol.exe. Some variants decrypt embedded resources and configuration data with combinations of XOR, DES or TripleDES, AES, GZip, and Protobuf-serialized configuration blobs before retrieving additional modules or configuration from command-and-control infrastructure.
Beyond credential and data theft, PureLogs has documented downloader functionality and can fetch and execute additional payloads or collect files from specified locations for exfiltration. Communications with command-and-control servers have been described using custom binary protocols, Protobuf with compression, and encrypted transport including 3DES, AES, and in newer variants TLS or HTTPS. The malware has appeared in broader intrusion chains alongside other Pure-family malware such as PureRAT and with payloads including ransomware, underscoring its role both as a commodity stealer and as an enabler of follow-on compromise.
C2 tracking
Derp observations, rolling seven-day window
Samples
9ee23101f6f2470da3ac84452a2a85ab5f5d3a966e39e211da4482a64e703da7 1e2d1ddf3fbd79437f795edd84d975e8398df3f45db455f6fa4c9320fbe45137 2fcad226b17131da4274e1b9f8f31359bdd325c9568665f08fd1f6c5d06a23ce a9302240e19030a057bb95b20d951a1e974008ca157a44cc18eadb4e88f0bd76 e59711c5e2e7d071d0810743998a21338951a33a96836a9861f08c58c6e07506 fa02ab08a5c04901998324f048d7c3d30db615e5f2435c13992b3221ff313598 Reported operators
After four stages of unpacking and injection, the PURELOGS stealer is now running inside the hollowed CasPol.exe process. PURELOGS is a commodity .NET infostealer that first appeared for sale on various underground forums in 2022.
These scripts systematically deploy the final payloads, which include the notorious Pay2Key ransomware, the PureLogs information stealer, and the PureRAT trojan.
Cyble Research and Intelligence Labs analyzes a spam campaign dropping PureLogs stealer aimed at Italian users... This tool is used by the Threat Actor (TA) “Alibaba2044” to launch a malicious spam campaign at targets based in Italy on the 14th of December 2022.
Cyble Research and Intelligence Labs analyzes a spam campaign dropping PureLogs stealer aimed at Italian users... This tool is used by the Threat Actor (TA) “Alibaba2044” to launch a malicious spam campaign at targets based in Italy on the 14th of December 2022.
MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.