Threats · 70 days ago
The break is the delivery path. A trusted-looking Blogspot chain can put PureLog Stealer straight into memory, so file hashes, disk scans, and simple URL reputation checks miss the part that matters most: the machine can be compromised without leaving a normal payload behind. Once that runs, the theft is not limited to passwords; it also grabs browser cookies and session data that can keep working after MFA.
Securonix says Veil#Drop starts on compromised sites, hands off to PowerShell, and then pulls later stages from Blogspot pages without writing files to disk. The final loader rebuilds .NET assemblies in memory, and the stealer targets browser passwords, cookies, autofill data, cryptocurrency wallets, and host details. Securonix also warned that stolen session cookies can be reused to bypass MFA by replaying an already logged-in session.
For defenders, the exposure is broader than one stealer family. Any environment that relies on browser sessions or cookie-based access is now facing a delivery path built to reduce forensic evidence and defeat reputation-based controls, with account takeover still possible long after the initial infection.
3 sources covering this story
Blogspot-Hosted Payloads Delivered in ‘Veil#Drop’ Attacks
Securonix says the sophisticated framework abuses compromised websites, Blogspot, PowerShell, and fileless techniques to evade detection and deploy the PureLog information stealer.
VEIL#DROP Malware Chain Uses Blogger Platform to Deliver PureLogs Stealer
Securonix says PureLogs infection starts with a fake PDF JavaScript file and uses PowerShell, fileless .NET loading, and LOLBins.
Veil#Drop Uses Google Blogspot to Deploy PureLog Stealer
Securonix said the Veil#Drop campaign abuses Google Blogspot to deliver PureLog Stealer in memory
Part of the PlainSec briefing for 2026-07-06