Session Tokens, Not Passwords, Are the Prize

This campaign is built to steal what keeps people signed in, not just harvest another password. It slips in through archive-wrapped JavaScript, then runs through a normal Windows process so defenders can miss the theft if they only hunt for a dropped executable. FortiGuard Labs says the PureLogs variant pulls browser cookies and session tokens, Discord auth data, and credentials for VPN and app logins from Windows systems. It targets Chrome, Edge, Brave, Opera, Yandex Browser, Firefox, Waterfox, LibreWolf, and Discord, and uses process hollowing inside MsBuild.exe to make the activity look like ordinary system behavior. That means password resets may leave an attacker’s session alive if the stolen cookies or tokens are still valid. For teams that rely on browser-backed SaaS sessions or Discord, the compromise can persist past the initial cleanup.

Part of the PlainSec briefing for 2026-05-28

Sources