Blogspot Delivery Hides a Session-Stealing Loader

The break is the delivery path. A trusted-looking Blogspot chain can put PureLog Stealer straight into memory, so file hashes, disk scans, and simple URL reputation checks miss the part that matters most: the machine can be compromised without leaving a normal payload behind. Once that runs, the theft is not limited to passwords; it also grabs browser cookies and session data that can keep working after MFA. Securonix says Veil#Drop starts on compromised sites, hands off to PowerShell, and then pulls later stages from Blogspot pages without writing files to disk. The final loader rebuilds .NET assemblies in memory, and the stealer targets browser passwords, cookies, autofill data, cryptocurrency wallets, and host details. Securonix also warned that stolen session cookies can be reused to bypass MFA by replaying an already logged-in session. For defenders, the exposure is broader than one stealer family. Any environment that relies on browser sessions or cookie-based access is now facing a delivery path built to reduce forensic evidence and defeat reputation-based controls, with account takeover still possible long after the initial infection.

Part of the PlainSec briefing for 2026-07-06

Sources