Skip to content
Malware family

PureLogs

PureLogs is a Windows-based .NET information stealer sold as a commodity malware-as-a-service offering since 2022 and associated with the Pure family of products developed by PureCoder.

Profile source: Mallory opens in a new tab

PureLogs

Family profile

PureLogs is a Windows-based .NET information stealer sold as a commodity malware-as-a-service offering since 2022 and associated with the Pure family of products developed by PureCoder. It is designed to harvest credentials, cookies, session tokens, autofill data, credit card data, browser history, Windows secrets, password manager data, cryptocurrency wallet files and keys, and data from numerous applications including Discord, Telegram, Steam, FileZilla, Outlook, Foxmail, MailBird, MailMaster, OpenVPN, ProtonVPN, Pidgin, and DownloadManager. Reported targeting includes more than 30 desktop cryptocurrency wallets, dozens of browsers, and large numbers of browser-based Web3 wallet extensions.

Observed delivery vectors include phishing campaigns using invoice- and purchase-order-themed lures, ZIP/RAR/TXZ archives containing malicious JavaScript or Windows Script Host JScript, ClickFix-style PowerShell execution, Blogger-hosted staging, archive.org-hosted polyglot PNG payloads, and steganographic PNG retrieval via the PawsRunner loader. PureLogs has also been delivered through malicious developer tooling, including a fake Solidity extension in Cursor AI/Open VSX, and has appeared in broader intrusion chains alongside malware such as PureCrypter, PureRAT, Pay2Key, Vidar, Quasar, Violet RAT, Remcos, and PowerLoader. Threat reporting links its use to campaigns attributed or associated with Fluffy Wolf, Hive0131 with low confidence, and the SERPENTINE#CLOUD activity cluster; Huntress also documented PureLogs in fake OpenClaw installer activity.

Behaviorally, PureLogs commonly executes filelessly and in memory, often after layered decryption, decompression, and reflective .NET loading. Multiple campaigns used process hollowing or injection into legitimate signed processes including CasPol.exe, MsBuild.exe, RegAsm.exe, InstallUtil.exe, and notepad.exe-context loaders. Samples and campaigns described anti-debugging, anti-sandbox, and anti-VM checks; process masquerading; mutex or registry-based single-instance control; self-deletion; and protection or obfuscation with .NET Reactor, IntelliLock, or ConfuserEx. Reported anti-analysis checks include virtualization artifact detection, debugger and tooling checks, sandbox heuristics, and geographic filtering to avoid CIS and Russian-speaking regions in at least one analyzed sample.

Configuration and communications vary by build and campaign. Reported implementations include Protobuf-serialized and XOR-encrypted configuration blobs, 3DES- or TripleDES-decrypted resources, AES-256-CBC encryption for exfiltration, PBKDF2-derived keys in some samples, gzip compression, HTTPS or raw TCP C2, and endpoint patterns such as /ping, /plugin, /userinfo, /browser, /application, /crypto, /discord, /filesearch/req, /filesearch/res, and /finish. PureLogs has been observed profiling victims via WMI and collecting host metadata such as username, domain, CPU, GPU, RAM, OS version, architecture, screen resolution, antivirus products, clipboard contents, screenshots, public IP, timezone, and geolocation.

Known indicators mentioned in reporting include C2 or delivery infrastructure such as 45.137.70.55:5888, 77.83.39.211:8443, 5.101.84.202, 178.16.52.232, 158.94.208.92, 144.172.112.84, canndelta.com, everycarebd.com/imagelkjh0987.png, archive.org-hosted PNG payloads, and angelic.su and lmfao.su infrastructure used in a developer-targeting campaign. Detection names cited in the content include HEUR:Trojan-PSW.MSIL.PureLogs.gen, JS/PureLogs.JAE!tr, PowerShell/PureLogs.DUQ!tr, MSIL/PureLogs.C702!tr, MSIL/PureLogs.YBT!tr, and MSIL/PureLogs.0EDE!tr.

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Jul 14, 2026
Last activity
Jul 19, 2026
Feed role
C2
Host form
4 IP / 0 hostnames

Leading locations

  • FR1
  • LU1
  • NL1
  • US1

Leading providers

  • GTHost2
  • Ghosty Networks LLC1
  • H4Y Technologies LLC1

Infrastructure traits

  • Hosting 4
  • Vpn 1

Samples

Recent associated samples

Reported operators

Threat actors

4 named in public reporting
hive0131

After four stages of unpacking and injection, the PURELOGS stealer is now running inside the hollowed CasPol.exe process. PURELOGS is a commodity .NET infostealer that first appeared for sale on various underground forums in 2022.

Fluffy Wolf

These scripts systematically deploy the final payloads, which include the notorious Pay2Key ransomware, the PureLogs information stealer, and the PureRAT trojan.

PureCoder

Cyble Research and Intelligence Labs analyzes a spam campaign dropping PureLogs stealer aimed at Italian users... This tool is used by the Threat Actor (TA) “Alibaba2044” to launch a malicious spam campaign at targets based in Italy on the 14th of December 2022.

Alibaba2044

Cyble Research and Intelligence Labs analyzes a spam campaign dropping PureLogs stealer aimed at Italian users... This tool is used by the Threat Actor (TA) “Alibaba2044” to launch a malicious spam campaign at targets based in Italy on the 14th of December 2022.

MITRE ATT&CK

PureLogs in ATT&CK

61 distinct techniques

Techniques

61 techniques
T1059.001 PowerShell T1560 Archive Collected Data T1140 Deobfuscate/Decode Files or Information T1555 Credentials from Password Stores T1204.002 Malicious File T1005 Data from Local System T1218 System Binary Proxy Execution T1027 Obfuscated Files or Information T1539 Steal Web Session Cookie T1027.003 Steganography T1552.004 Private Keys T1055.012 Process Hollowing T1105 Ingress Tool Transfer T1555.003 Credentials from Web Browsers T1047 Windows Management Instrumentation T1620 Reflective Code Loading T1041 Exfiltration Over C2 Channel T1027.011 Fileless Storage T1055 Process Injection T1566 Phishing T1070.004 File Deletion T1548.002 Bypass User Account Control T1003 OS Credential Dumping T1071 Application Layer Protocol T1012 Query Registry T1547.001 Registry Run Keys / Startup Folder T1497 Virtualization/Sandbox Evasion T1082 System Information Discovery T1497.001 System Checks T1036 Masquerading T1622 Debugger Evasion T1070 Indicator Removal T1566.001 Spearphishing Attachment T1059.007 JavaScript T1189 Drive-by Compromise T1649 Steal or Forge Authentication Certificates T1059.005 Visual Basic T1195 Supply Chain Compromise T1528 Steal Application Access Token T1113 Screen Capture T1127.001 MSBuild T1071.001 Web Protocols T1115 Clipboard Data T1059 Command and Scripting Interpreter T1566.002 Spearphishing Link T1213 Data from Information Repositories T1057 Process Discovery T1033 System Owner/User Discovery T1562.006 Indicator Blocking T1562 Impair Defenses T1027.013 Encrypted/Encoded File T1583.001 Domains T1055.004 Asynchronous Procedure Call T1106 Native API T1059.003 Windows Command Shell T1059.006 Python T1574.001 DLL T1204 User Execution T1083 File and Directory Discovery T1020 Automated Exfiltration T1119 Automated Collection

Reporting

Research mentioning PureLogs

Jul 1
The Hacker News

VEIL#DROP Malware Chain Uses Blogger Platform to Deliver PureLogs Stealer

...ultimately leading to the deployment of PureLogs Stealer, a .NET-based infostealer known for harvesting a wide array of sensitive data from compromised hosts.

Jun 16
Security Online Info

Fluffy Wolf Phishing Attacks Push PowerLoader Malware

These scripts systematically deploy the final payloads, which include the notorious Pay2Key ransomware, the PureLogs information stealer, and the PureRAT trojan.

Jun 3
Gurucul Threat Research

Canndelta ClickFix Campaign Abusing Donut Shellcode to Deploy PureLogs Stealer | Community Portal | Gurucul

This research analyzes a ClickFix campaign leveraging the spoofed licensing-themed website canndelta.com to deliver the PureLogs stealer through malicious PowerShell commands.

May 29
Security Online Info

PureLogs Info Stealer Campaign: Evasive Phishing Exposed

FortiGuard Labs identified a highly deceptive PureLogs info stealer campaign spreading through corporate networks.

May 28
Cyber Security News

New PureLogs Variant Uses MsBuild.exe Process Hollowing to Evade Detection

A new and dangerous version of the PureLogs information-stealing malware has emerged... The final payload, PureLogs itself, is a .NET-based infostealer built to harvest credentials, browser data, cryptocurrency wallet files, and more.

May 28
Xakep

Группировка Fluffy Wolf атаковала российские компании новой малварью - Хакер

Внутри архивов находились различные загрузчики и дропперы, предназначенные для доставки вредоносов PureLogs, PureRAT и шифровальщика Pay2Key.

May 27
Gurucul Threat Research

Phishing Campaign Deploys JavaScript-Driven PureLogs Variant to Steal Sensitive Data | Community Portal | Gurucul

We recently uncovered a phishing campaign delivering a variant of PureLogs, an infostealer designed to harvest sensitive data from compromised devices.

May 26
Fortinet Threat Research

Phishing Campaign Deploys JavaScript-Driven PureLogs Variant to Steal Sensitive Data | FortiGuard Labs

FortiGuard Labs recently identified a phishing campaign distributing a PureLogs variant designed to collect sensitive data from the victim’s device.

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.