Skip to content

PureLogs

PureLogs is a Windows-focused .NET infostealer sold as a malware-as-a-service offering and associated with the Pure family of crimeware developed by PureCoder.

Profile source: Mallory opens in a new tab

PureLogs

Family profile

PureLogs is a Windows-focused .NET infostealer sold as a malware-as-a-service offering and associated with the Pure family of crimeware developed by PureCoder. Active since at least 2022, it is commonly deployed as a final-stage payload by loaders and crypters such as PureCrypter, Donut-based loaders, VMDetectLoader, and steganographic or fileless delivery chains. Observed campaigns have used phishing, archive-borne JavaScript or script launchers, fake software installers, ClickFix lures, and trojanized developer tooling or extensions to deliver the malware, including operations targeting enterprises, Russian organizations, and cryptocurrency users and developers.

Its primary function is theft and exfiltration of sensitive data from infected Windows hosts. PureLogs targets browser-stored credentials, cookies, session tokens, autofill data, payment-card data, Discord and other messaging-platform tokens, VPN credentials, email-client data, FTP client data, cryptocurrency wallet applications, and numerous browser extensions tied to wallets, password managers, and authenticators. Reported targeting includes Chromium- and Gecko-based browsers as well as applications such as Outlook, Thunderbird, Foxmail, Mailbird, FileZilla, WinSCP, Steam, Telegram, Signal, Discord, OpenVPN, and Proton VPN. Multiple reports also describe theft of host profiling data, screenshots, clipboard contents, antivirus information, and other system metadata.

PureLogs commonly uses staged, memory-resident execution and defense-evasion techniques. Observed tradecraft includes heavy obfuscation and commercial protectors such as .NET Reactor and IntelliLock, anti-debugging, anti-sandbox and anti-VM checks, mutex-based single-instance control, self-deletion, reflective .NET loading, and process injection or process hollowing into trusted Windows binaries such as MsBuild.exe, InstallUtil.exe, and CasPol.exe. Some variants decrypt embedded resources and configuration data with combinations of XOR, DES or TripleDES, AES, GZip, and Protobuf-serialized configuration blobs before retrieving additional modules or configuration from command-and-control infrastructure.

Beyond credential and data theft, PureLogs has documented downloader functionality and can fetch and execute additional payloads or collect files from specified locations for exfiltration. Communications with command-and-control servers have been described using custom binary protocols, Protobuf with compression, and encrypted transport including 3DES, AES, and in newer variants TLS or HTTPS. The malware has appeared in broader intrusion chains alongside other Pure-family malware such as PureRAT and with payloads including ransomware, underscoring its role both as a commodity stealer and as an enabler of follow-on compromise.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Exfiltration
  • Post Exploitation
  • Process Injection
  • Session Hijacking

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 27, 2026
Last activity
Sep 2, 2026
Feed role
C2 / Distribution
Host form
4 IP / 5 hostnames

Leading locations

  • DE2
  • LU2
  • BE1
  • CA1
  • FI1
  • NL1
  • US1

Leading providers

  • Ghosty Networks LLC2
  • VPSLab Networks2
  • Amarutu Technology Ltd1
  • Cloudflare, Inc.1
  • Combell NV1
  • Hetzner Online GmbH1

Infrastructure traits

  • Hosting 9
  • Anycast 1

Samples

Recent associated samples

Reported operators

Threat actors

4 named in public reporting
hive0131

After four stages of unpacking and injection, the PURELOGS stealer is now running inside the hollowed CasPol.exe process. PURELOGS is a commodity .NET infostealer that first appeared for sale on various underground forums in 2022.

Fluffy Wolf

These scripts systematically deploy the final payloads, which include the notorious Pay2Key ransomware, the PureLogs information stealer, and the PureRAT trojan.

PureCoder

Cyble Research and Intelligence Labs analyzes a spam campaign dropping PureLogs stealer aimed at Italian users... This tool is used by the Threat Actor (TA) “Alibaba2044” to launch a malicious spam campaign at targets based in Italy on the 14th of December 2022.

Alibaba2044

Cyble Research and Intelligence Labs analyzes a spam campaign dropping PureLogs stealer aimed at Italian users... This tool is used by the Threat Actor (TA) “Alibaba2044” to launch a malicious spam campaign at targets based in Italy on the 14th of December 2022.

MITRE ATT&CK

PureLogs in ATT&CK

63 distinct techniques

Techniques

63 techniques
T1555 Credentials from Password Stores T1573 Encrypted Channel T1055 Process Injection T1071 Application Layer Protocol T1555.003 Credentials from Web Browsers T1041 Exfiltration Over C2 Channel T1105 Ingress Tool Transfer T1218.004 InstallUtil T1560 Archive Collected Data T1566 Phishing T1566.002 Spearphishing Link T1059.001 PowerShell T1140 Deobfuscate/Decode Files or Information T1204.002 Malicious File T1005 Data from Local System T1218 System Binary Proxy Execution T1027 Obfuscated Files or Information T1539 Steal Web Session Cookie T1027.003 Steganography T1552.004 Private Keys T1055.012 Process Hollowing T1047 Windows Management Instrumentation T1620 Reflective Code Loading T1027.011 Fileless Storage T1070.004 File Deletion T1548.002 Bypass User Account Control T1003 OS Credential Dumping T1012 Query Registry T1547.001 Registry Run Keys / Startup Folder T1497 Virtualization/Sandbox Evasion T1082 System Information Discovery T1497.001 System Checks T1036 Masquerading T1622 Debugger Evasion T1070 Indicator Removal T1566.001 Spearphishing Attachment T1059.007 JavaScript T1189 Drive-by Compromise T1649 Steal or Forge Authentication Certificates T1059.005 Visual Basic T1195 Supply Chain Compromise T1528 Steal Application Access Token T1113 Screen Capture T1127.001 MSBuild T1071.001 Web Protocols T1115 Clipboard Data T1059 Command and Scripting Interpreter T1213 Data from Information Repositories T1057 Process Discovery T1033 System Owner/User Discovery T1562.006 Indicator Blocking T1562 Impair Defenses T1027.013 Encrypted/Encoded File T1583.001 Domains T1055.004 Asynchronous Procedure Call T1106 Native API T1059.003 Windows Command Shell T1059.006 Python T1574.001 DLL T1204 User Execution T1083 File and Directory Discovery T1020 Automated Exfiltration T1119 Automated Collection

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.