PureLogs Stealer Campaign Using PNG Steganography
Score: 8/10

PureLogs Stealer Campaign Using PNG Steganography

A multi-stage PureLogs Stealer campaign impersonates Adobe Sign to deliver fileless payloads via image steganography and environment variable manipulation.

Executive Summary

Threat actors are executing a sophisticated campaign impersonating Adobe Sign (chickplaybox[.]com) to distribute PureLogs Stealer. The attack chain is notable for its heavy reliance on anti-forensic techniques, including fingerprinting victims via Cloudflare Turnstile and ipapi.co before delivering a multi-stage infection process.

Technically, the malware avoids disk writes by storing encoded payload fragments across hundreds of process environment variables, which are then reassembled and reflectively loaded by PowerShell. The final stage involves downloading a PNG image from PixelDrain, where the core stealer payload is extracted from the 'iTXt' metadata chunk and decrypted using a Linear Congruential Generator (LCG)-based XOR routine.

This campaign represents a significant threat due to its high level of evasion, effectively bypassing traditional signature-based detection. The use of legitimate file-sharing services for payload delivery and the abuse of standard Windows management tools for fileless execution increase the risk of successful data exfiltration and credential theft across targeted organizations.

Key Details

Threat Name

PureLogs Stealer

Affects

—

Adversary

—

Malware/Tools

PureLogs Stealer

Report Score

8out of 10
Quality Score
Good
IOC Quality8
TTP Details9
Detection Guidance6
Enterprise Relevance9
Clarity & Structure9
Technical Depth9

Sources