Threats · 111 days ago
This campaign is built to steal what keeps people signed in, not just harvest another password. It slips in through archive-wrapped JavaScript, then runs through a normal Windows process so defenders can miss the theft if they only hunt for a dropped executable.
FortiGuard Labs says the PureLogs variant pulls browser cookies and session tokens, Discord auth data, and credentials for VPN and app logins from Windows systems. It targets Chrome, Edge, Brave, Opera, Yandex Browser, Firefox, Waterfox, LibreWolf, and Discord, and uses process hollowing inside MsBuild.exe to make the activity look like ordinary system behavior.
That means password resets may leave an attacker’s session alive if the stolen cookies or tokens are still valid. For teams that rely on browser-backed SaaS sessions or Discord, the compromise can persist past the initial cleanup.
1 source covering this story
PureLogs Variant Steals Data via Purchase Order Lures
FortiGuard Labs detailed a PureLogs campaign using JavaScript, PowerShell and process hollowing
Part of the PlainSec briefing for 2026-05-28