Last seven days
- First activity
- Jul 14, 2026
- Last activity
- Jul 19, 2026
- Feed role
- C2
- Host form
- 4 IP / 0 hostnames
PureLogs is a Windows-based .NET information stealer sold as a commodity malware-as-a-service offering since 2022 and associated with the Pure family of products developed by PureCoder.
Profile source: Mallory opens in a new tabPureLogs
PureLogs is a Windows-based .NET information stealer sold as a commodity malware-as-a-service offering since 2022 and associated with the Pure family of products developed by PureCoder. It is designed to harvest credentials, cookies, session tokens, autofill data, credit card data, browser history, Windows secrets, password manager data, cryptocurrency wallet files and keys, and data from numerous applications including Discord, Telegram, Steam, FileZilla, Outlook, Foxmail, MailBird, MailMaster, OpenVPN, ProtonVPN, Pidgin, and DownloadManager. Reported targeting includes more than 30 desktop cryptocurrency wallets, dozens of browsers, and large numbers of browser-based Web3 wallet extensions.
Observed delivery vectors include phishing campaigns using invoice- and purchase-order-themed lures, ZIP/RAR/TXZ archives containing malicious JavaScript or Windows Script Host JScript, ClickFix-style PowerShell execution, Blogger-hosted staging, archive.org-hosted polyglot PNG payloads, and steganographic PNG retrieval via the PawsRunner loader. PureLogs has also been delivered through malicious developer tooling, including a fake Solidity extension in Cursor AI/Open VSX, and has appeared in broader intrusion chains alongside malware such as PureCrypter, PureRAT, Pay2Key, Vidar, Quasar, Violet RAT, Remcos, and PowerLoader. Threat reporting links its use to campaigns attributed or associated with Fluffy Wolf, Hive0131 with low confidence, and the SERPENTINE#CLOUD activity cluster; Huntress also documented PureLogs in fake OpenClaw installer activity.
Behaviorally, PureLogs commonly executes filelessly and in memory, often after layered decryption, decompression, and reflective .NET loading. Multiple campaigns used process hollowing or injection into legitimate signed processes including CasPol.exe, MsBuild.exe, RegAsm.exe, InstallUtil.exe, and notepad.exe-context loaders. Samples and campaigns described anti-debugging, anti-sandbox, and anti-VM checks; process masquerading; mutex or registry-based single-instance control; self-deletion; and protection or obfuscation with .NET Reactor, IntelliLock, or ConfuserEx. Reported anti-analysis checks include virtualization artifact detection, debugger and tooling checks, sandbox heuristics, and geographic filtering to avoid CIS and Russian-speaking regions in at least one analyzed sample.
Configuration and communications vary by build and campaign. Reported implementations include Protobuf-serialized and XOR-encrypted configuration blobs, 3DES- or TripleDES-decrypted resources, AES-256-CBC encryption for exfiltration, PBKDF2-derived keys in some samples, gzip compression, HTTPS or raw TCP C2, and endpoint patterns such as /ping, /plugin, /userinfo, /browser, /application, /crypto, /discord, /filesearch/req, /filesearch/res, and /finish. PureLogs has been observed profiling victims via WMI and collecting host metadata such as username, domain, CPU, GPU, RAM, OS version, architecture, screen resolution, antivirus products, clipboard contents, screenshots, public IP, timezone, and geolocation.
Known indicators mentioned in reporting include C2 or delivery infrastructure such as 45.137.70.55:5888, 77.83.39.211:8443, 5.101.84.202, 178.16.52.232, 158.94.208.92, 144.172.112.84, canndelta.com, everycarebd.com/imagelkjh0987.png, archive.org-hosted PNG payloads, and angelic.su and lmfao.su infrastructure used in a developer-targeting campaign. Detection names cited in the content include HEUR:Trojan-PSW.MSIL.PureLogs.gen, JS/PureLogs.JAE!tr, PowerShell/PureLogs.DUQ!tr, MSIL/PureLogs.C702!tr, MSIL/PureLogs.YBT!tr, and MSIL/PureLogs.0EDE!tr.
C2 tracking
Derp observations, rolling seven-day window
Samples
Reported operators
After four stages of unpacking and injection, the PURELOGS stealer is now running inside the hollowed CasPol.exe process. PURELOGS is a commodity .NET infostealer that first appeared for sale on various underground forums in 2022.
These scripts systematically deploy the final payloads, which include the notorious Pay2Key ransomware, the PureLogs information stealer, and the PureRAT trojan.
Cyble Research and Intelligence Labs analyzes a spam campaign dropping PureLogs stealer aimed at Italian users... This tool is used by the Threat Actor (TA) “Alibaba2044” to launch a malicious spam campaign at targets based in Italy on the 14th of December 2022.
Cyble Research and Intelligence Labs analyzes a spam campaign dropping PureLogs stealer aimed at Italian users... This tool is used by the Threat Actor (TA) “Alibaba2044” to launch a malicious spam campaign at targets based in Italy on the 14th of December 2022.
MITRE ATT&CK
Reporting
...ultimately leading to the deployment of PureLogs Stealer, a .NET-based infostealer known for harvesting a wide array of sensitive data from compromised hosts.
These scripts systematically deploy the final payloads, which include the notorious Pay2Key ransomware, the PureLogs information stealer, and the PureRAT trojan.
This research analyzes a ClickFix campaign leveraging the spoofed licensing-themed website canndelta.com to deliver the PureLogs stealer through malicious PowerShell commands.
FortiGuard Labs identified a highly deceptive PureLogs info stealer campaign spreading through corporate networks.
A new and dangerous version of the PureLogs information-stealing malware has emerged... The final payload, PureLogs itself, is a .NET-based infostealer built to harvest credentials, browser data, cryptocurrency wallet files, and more.
Внутри архивов находились различные загрузчики и дропперы, предназначенные для доставки вредоносов PureLogs, PureRAT и шифровальщика Pay2Key.
We recently uncovered a phishing campaign delivering a variant of PureLogs, an infostealer designed to harvest sensitive data from compromised devices.
FortiGuard Labs recently identified a phishing campaign distributing a PureLogs variant designed to collect sensitive data from the victim’s device.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.