Executive Summary
Threat actors are executing a sophisticated campaign impersonating Adobe Sign (chickplaybox[.]com) to distribute PureLogs Stealer. The attack chain is notable for its heavy reliance on anti-forensic techniques, including fingerprinting victims via Cloudflare Turnstile and ipapi.co before delivering a multi-stage infection process.
Technically, the malware avoids disk writes by storing encoded payload fragments across hundreds of process environment variables, which are then reassembled and reflectively loaded by PowerShell. The final stage involves downloading a PNG image from PixelDrain, where the core stealer payload is extracted from the 'iTXt' metadata chunk and decrypted using a Linear Congruential Generator (LCG)-based XOR routine.
This campaign represents a significant threat due to its high level of evasion, effectively bypassing traditional signature-based detection. The use of legitimate file-sharing services for payload delivery and the abuse of standard Windows management tools for fileless execution increase the risk of successful data exfiltration and credential theft across targeted organizations.
